PT-2018-18364 · Huawei · Huawei Usg9500+7
Published
2018-07-04
·
Updated
2019-10-03
·
CVE-2018-7994
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Huawei IPS Module versions V500R001C50
Huawei NGFW Module versions V500R001C50; V500R002C10
Huawei NIP6300 versions V500R001C50
Huawei NIP6600 versions V500R001C50
Huawei NIP6800 versions V500R001C50
Huawei Secospace USG6600 versions V500R001C50
Huawei USG9500 versions V500R001C50
Description:
The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot of questionnaires to the device, and a successful exploit could cause the device to reboot since it runs out of memory.
Recommendations:
For Huawei IPS Module version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei NGFW Module versions V500R001C50 and V500R002C10, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei NIP6300 version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei NIP6600 version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei NIP6800 version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei Secospace USG6600 version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
For Huawei USG9500 version V500R001C50, update the software to a version that properly releases allocated memory when processing questionnaires.
As a temporary workaround, consider restricting the number of questionnaires that can be sent to the device to minimize the risk of exploitation.
Fix
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ips Module
Huawei Ngfw Module
Huawei Nip6300
Huawei Nip6600
Huawei Nip6800
Huawei Secospace Usg6600
Huawei Usg9500
Huawei Vrp