PT-2017-14760 · Huawei · Huawei Ar200+12
Published
2017-12-15
·
Updated
2018-03-09
·
CVE-2017-17299
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei AR120-S versions V200R006C10 through V200R007C00
Huawei AR1200 versions V200R006C10 through V200R007C02
Huawei AR1200-S versions V200R006C10 through V200R008C20
Huawei AR150 versions V200R006C10 through V200R007C02
Huawei AR150-S versions V200R006C10 through V200R007C00
Huawei AR160 versions V200R006C10 through V200R007C02
Huawei AR200 versions V200R006C10 through V200R007C00
Huawei AR200-S versions V200R006C10 through V200R007C00
Huawei AR2200 versions V200R006C10 through V200R007C02
Huawei AR2200-S versions V200R006C10 through V200R008C20
Huawei AR3200 versions V200R006C10 through V200R007C02
Huawei AR3600 versions V200R006C10 through V200R007C00
Huawei AR510 versions V200R006C12 through V200R007C00
Huawei IPS Module version V500R001C30
Huawei NIP6300 version V500R001C30
Huawei NetEngine16EX versions V200R006C10 through V200R007C00
Description
The issue is related to an insufficient input validation vulnerability. An unauthenticated, remote attacker may send crafted IKE V2 messages to the affected products. Due to the insufficient validation of the messages, successful exploit will cause invalid memory access and result in a denial of service on the affected products.
Recommendations
For Huawei AR120-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei AR1200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue.
For Huawei AR1200-S versions V200R006C10 through V200R008C20, update to a fixed version to resolve the issue.
For Huawei AR150 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue.
For Huawei AR150-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei AR160 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue.
For Huawei AR200 versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei AR200-S versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei AR2200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue.
For Huawei AR2200-S versions V200R006C10 through V200R008C20, update to a fixed version to resolve the issue.
For Huawei AR3200 versions V200R006C10 through V200R007C02, update to a fixed version to resolve the issue.
For Huawei AR3600 versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei AR510 versions V200R006C12 through V200R007C00, update to a fixed version to resolve the issue.
For Huawei IPS Module version V500R001C30, update to a fixed version to resolve the issue.
For Huawei NIP6300 version V500R001C30, update to a fixed version to resolve the issue.
For Huawei NetEngine16EX versions V200R006C10 through V200R007C00, update to a fixed version to resolve the issue.
As a temporary workaround, consider restricting access to IKE V2 messages to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ar120-S
Huawei Ar1200
Huawei Ar150
Huawei Ar160
Huawei Ar200
Huawei Ar2200
Huawei Ar3200
Huawei Ar3600
Huawei Ar510
Huawei Ips Module
Huawei Nip6300
Huawei Netengine16Ex
Huawei Vrp