PT-2017-18205 · Huawei · Tp3206+2

Published

2017-11-22

·

Updated

2019-10-03

·

CVE-2017-8201

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MAX PRESENCE V100R001C00 TP3106 V100R002C00 TP3206 V100R002C00
Description The issue is related to a memory leak in the H323 protocol. An attacker can exploit this by sending crafted packets to the system after logging in as a user. Due to insufficient verification of these packets, a successful exploit could lead to a memory leak, resulting in a denial of service (DoS) condition.
Recommendations For MAX PRESENCE V100R001C00, update the H323 protocol implementation to properly verify incoming packets. For TP3106 V100R002C00, restrict access to the H323 protocol until a patch is available to fix the memory leak issue. For TP3206 V100R002C00, consider disabling the H323 protocol temporarily as a workaround until a fix is provided.

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8201

Affected Products

Max Presence
Tp3106
Tp3206