PT-2021-22785 · Huawei · Ese620X Vess+1
Published
2021-12-01
·
Updated
2022-07-15
·
CVE-2021-39999
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
eSE620X vESS versions V100R001C10SPC200 through V100R001C20SPC200
DOPRA SSP products (affected versions not specified)
Description
The issue is related to a buffer overflow due to insufficient validation of packets. An attacker can exploit this by sending a specific message to the target device, potentially causing a denial of service condition.
Recommendations
For eSE620X vESS versions V100R001C10SPC200 through V100R001C20SPC200, consider implementing packet validation to prevent buffer overflow.
For DOPRA SSP products, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Vrp
Ese620X Vess