PT-2021-2657 · Huawei · Huawei Secospace Usg6500+6

Published

2021-02-10

·

Updated

2021-04-20

·

CVE-2021-22312

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Huawei IPS Module (affected versions not specified) Huawei NGFW Module (affected versions not specified) Huawei Secospace USG6300 (affected versions not specified) Huawei Secospace USG6500 (affected versions not specified) Huawei Secospace USG6600 (affected versions not specified) Huawei USG9500 (affected versions not specified)
Description The issue is related to a memory leak, where an authenticated remote attacker can exploit the vulnerability by sending a specific message to the affected product. This can cause service abnormalities due to improper memory allocation release. The vulnerability may allow a remote attacker to cause a denial of service.
Recommendations For Huawei IPS Module, update to a version that properly releases allocated memory to prevent service abnormalities. For Huawei NGFW Module, ensure that all allocated memory is properly released after use to mitigate the risk of service disruption. For Huawei Secospace USG6300, restrict access to the module until a patch is available that fixes the memory leak issue. For Huawei Secospace USG6500, consider disabling the affected service temporarily until a fix is applied. For Huawei Secospace USG6600, apply configuration changes to minimize the impact of the memory leak on system performance. For Huawei USG9500, as a temporary workaround, consider implementing additional monitoring to quickly identify and respond to service abnormalities caused by the memory leak.

Fix

Use After Free

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02186
CVE-2021-22312

Affected Products

Huawei Ips Module
Huawei Ngfw Module
Huawei Secospace Usg6300
Huawei Secospace Usg6500
Huawei Secospace Usg6600
Huawei Usg9500
Huawei Vrp