PT-2018-6405 · Huawei · Huawei Vp9660

Published

2018-03-05

·

Updated

2018-03-27

·

CVE-2017-17133

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Huawei VP9660 version V500R002C10
Description: The issue is related to a null pointer reference vulnerability in the license module due to insufficient verification. An authenticated local attacker could exploit this by placing a malicious license file into the system, causing memory null pointer accessing and related processing to crash, leading to a denial of service.
Recommendations: For Huawei VP9660 version V500R002C10, ensure proper verification of license files to prevent malicious files from being placed into the system. As a temporary workaround, consider restricting access to the license module to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17133

Affected Products

Huawei Vp9660