PT-2018-6405 · Huawei · Huawei Vp9660
Published
2018-03-05
·
Updated
2018-03-27
·
CVE-2017-17133
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Huawei VP9660 version V500R002C10
Description:
The issue is related to a null pointer reference vulnerability in the license module due to insufficient verification. An authenticated local attacker could exploit this by placing a malicious license file into the system, causing memory null pointer accessing and related processing to crash, leading to a denial of service.
Recommendations:
For Huawei VP9660 version V500R002C10, ensure proper verification of license files to prevent malicious files from being placed into the system. As a temporary workaround, consider restricting access to the license module to minimize the risk of exploitation.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Vp9660