PT-2021-7549 · Huawei · Huawei Nip6600+11
Published
2021-10-20
·
Updated
2021-10-28
·
CVE-2021-37129
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei IPS Module versions V500R005C00 through V500R005C20
Huawei NGFW Module version V500R005C00
Huawei NIP6600 versions V500R005C00 through V500R005C20
Huawei S12700 versions V200R010C00SPC600 through V200R020C10
Huawei S1700 versions V200R010C00SPC600 through V200R011C10SPC600
Huawei S2700 versions V200R010C00SPC600 through V200R011C10SPC600
Huawei S5700 versions V200R010C00SPC600 through V200R019C00SPC500
Huawei S6700 versions V200R010C00SPC600 through V200R011C10SPC600
Huawei S7700 versions V200R010C00SPC600 through V200R011C10SPC600
Huawei S9700 versions V200R010C00SPC600 through V200R011C10SPC600
Huawei USG9500 versions V500R005C00 through V500R005C20
Description
The issue is caused by a function of a module that does not properly verify the
input parameter, leading to an out of bounds write vulnerability. Successful exploitation could cause an out of bounds write, resulting in a denial of service condition. This can be achieved by sending specially crafted NETCONF packets to the device.Recommendations
For Huawei IPS Module versions V500R005C00 through V500R005C20, update to a fixed version.
For Huawei NGFW Module version V500R005C00, update to a fixed version.
For Huawei NIP6600 versions V500R005C00 through V500R005C20, update to a fixed version.
For Huawei S12700 versions V200R010C00SPC600 through V200R020C10, update to a fixed version.
For Huawei S1700 versions V200R010C00SPC600 through V200R011C10SPC600, update to a fixed version.
For Huawei S2700 versions V200R010C00SPC600 through V200R011C10SPC600, update to a fixed version.
For Huawei S5700 versions V200R010C00SPC600 through V200R019C00SPC500, update to a fixed version.
For Huawei S6700 versions V200R010C00SPC600 through V200R011C10SPC600, update to a fixed version.
For Huawei S7700 versions V200R010C00SPC600 through V200R011C10SPC600, update to a fixed version.
For Huawei S9700 versions V200R010C00SPC600 through V200R011C10SPC600, update to a fixed version.
For Huawei USG9500 versions V500R005C00 through V500R005C20, update to a fixed version.
As a temporary workaround, consider disabling the vulnerable module until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the
input parameter in the affected module until the issue is resolved.Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ips Module
Huawei Ngfw Module
Huawei Nip6600
Huawei S12700
Huawei S1700
Huawei S2700
Huawei S5700
Huawei S6700
Huawei S7700
Huawei S9700
Huawei Usg9500
Huawei Vrp