PT-2017-18156 · Huawei · Cloudengine 6800+23

Adi Sosnovich

+2

·

Published

2017-07-20

·

Updated

2017-12-08

·

CVE-2017-8147

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AC6005 version V200R006C10SPC200 AC6605 version V200R006C10SPC200 AR1200 versions V200R005C10CP0582T through V200R005C10HP0581T, V200R005C20SPC026T AR200 version V200R005C20SPC026T AR3200 version V200R005C20SPC026T CloudEngine 12800 versions V100R003C00 through V100R006C00, V200R001C00 CloudEngine 5800 versions V100R003C00 through V100R006C00, V200R001C00 CloudEngine 6800 versions V100R003C00 through V100R006C00, V200R001C00 CloudEngine 7800 versions V100R003C00 through V100R006C00, V200R001C00 CloudEngine 8800 versions V100R006C00, V200R001C00 E600 version V200R008C00 S12700 versions V200R005C00 through V200R008C00 S1700 versions V100R006C00 through V100R007C00, V200R006C00 S2300 versions V100R005C00 through V100R008C00 S2700 versions V100R005C00 through V100R008C00 S5300 versions V100R005C00 through V100R008C00 S5700 versions V100R005C00 through V100R008C00 S6300 versions V100R006C00, V200R001C00 through V200R008C00 S6700 versions V100R006C00, V200R001C00 through V200R008C00 S7700 versions V100R003C00, V100R006C00, V200R001C00 through V200R008C00 S9300 versions V100R001C00 through V100R008C00, V200R008C10 S9700 versions V200R001C00 through V200R008C00 Secospace USG6600 version V500R001C00SPC050
Description The issue is due to improper OSPF implementation, which can be exploited when the device receives special LSA packets, setting the LS age to MaxAge, 3600 seconds. This can lead to route table poisoning and a DoS attack.
Recommendations For each affected version, update the software to a version that is not vulnerable to this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8147

Affected Products

Ac6005
Ac6605
Ar1200
Ar200
Ar3200
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Cloudengine 8800
E600
Huawei Vrp
S12700
S1700
S2300
S2700
S5300
S5700
S6300
S6700
S7700
S9300
S9700
Secospace Usg6600