PT-2018-6425 · Huawei · Te50+6

Published

2018-03-09

·

Updated

2019-12-23

·

CVE-2017-17169

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DP300 versions V500R002C00 through V500R002C00SPCa00 RP200 versions V500R002C00SPC200 through V600R006C00SPC500 TE30 versions V100R001C10SPC300 through V600R006C00SPC500 TE40 versions V500R002C00SPC600 through V600R006C00SPC500 TE50 versions V500R002C00SPC600 through V600R006C00SPC500 TE60 versions V100R001C10 through V600R006C00SPC500 eSpace U1981 version V200R003C20SPC900
Description: The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnormal.
Recommendations: For DP300 versions V500R002C00 through V500R002C00SPCa00, update to a version that includes the fix for the input validation vulnerabilities. For RP200 versions V500R002C00SPC200 through V600R006C00SPC500, update to a version that includes the fix for the input validation vulnerabilities. For TE30 versions V100R001C10SPC300 through V600R006C00SPC500, update to a version that includes the fix for the input validation vulnerabilities. For TE40 versions V500R002C00SPC600 through V600R006C00SPC500, update to a version that includes the fix for the input validation vulnerabilities. For TE50 versions V500R002C00SPC600 through V600R006C00SPC500, update to a version that includes the fix for the input validation vulnerabilities. For TE60 versions V100R001C10 through V600R006C00SPC500, update to a version that includes the fix for the input validation vulnerabilities. For eSpace U1981 version V200R003C20SPC900, update to a version that includes the fix for the input validation vulnerabilities.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17169

Affected Products

Dp300
Rp200
Te30
Te40
Te50
Te60
Espace U1981