PT-2017-14729 · Huawei · Huawei S2700+8
Published
2017-12-06
·
Updated
2019-10-03
·
CVE-2017-17141
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Huawei S12700 versions V200R005C00 through V200R009C00
Huawei S1700 versions V200R006C10 through V200R009C00
Huawei S2700 versions V100R006C03 through V200R009C00
Huawei S3700 version V100R006C03
Huawei S5700 versions V200R001C00 through V200R009C00
Huawei S6700 versions V200R001C00 through V200R009C00
Huawei S7700 versions V200R001C00 through V200R009C00
Huawei S9700 versions V200R001C00 through V200R009C00
Description
The issue is related to a memory leak vulnerability in certain Huawei products. When attackers send specific malformed MPLS Service PING messages to the affected products under specific conditions, the products fail to release the memory when handling the packets, resulting in a memory leak.
Recommendations
For Huawei S12700 versions V200R005C00 through V200R009C00, restrict access to the MPLS Service PING messages to minimize the risk of exploitation.
For Huawei S1700 versions V200R006C10 through V200R009C00, consider disabling the handling of MPLS Service PING messages until a patch is available.
For Huawei S2700 versions V100R006C03 through V200R009C00, avoid using the vulnerable function related to MPLS Service PING message handling.
For Huawei S3700 version V100R006C03, restrict access to the vulnerable module to minimize the risk of exploitation.
For Huawei S5700 versions V200R001C00 through V200R009C00, consider applying configuration changes to limit the impact of the memory leak.
For Huawei S6700 versions V200R001C00 through V200R009C00, temporarily disable the handling of MPLS Service PING messages until a patch is available.
For Huawei S7700 versions V200R001C00 through V200R009C00, restrict access to the vulnerable API endpoint related to MPLS Service PING messages.
For Huawei S9700 versions V200R001C00 through V200R009C00, consider applying configuration changes to limit the impact of the memory leak.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei S12700
Huawei S1700
Huawei S2700
Huawei S3700
Huawei S5700
Huawei S6700
Huawei S7700
Huawei S9700
Huawei Vrp