PT-2022-6030 · Huawei · Cloudengine 12800+4
Published
2022-01-20
·
Updated
2022-02-04
·
CVE-2021-40042
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
CloudEngine 12800 versions V200R019C10SPC800 through V200R019C10SPC900
CloudEngine 5800 versions V200R019C10SPC800 through V200R020C00SPC600
CloudEngine 6800 versions V200R019C10SPC800 through V300R020C00SPC200
CloudEngine 7800 version V200R019C10SPC800
Description
The issue is related to an invalid pointer vulnerability in some Huawei products. Successful exploitation may cause process and service abnormalities. The vulnerability can be exploited by a remote attacker using specially crafted messages, potentially leading to a denial of service.
Recommendations
For CloudEngine 12800 versions V200R019C10SPC800 through V200R019C10SPC900, update to a fixed version to resolve the issue.
For CloudEngine 5800 versions V200R019C10SPC800 through V200R020C00SPC600, update to a fixed version to resolve the issue.
For CloudEngine 6800 versions V200R019C10SPC800 through V300R020C00SPC200, update to a fixed version to resolve the issue.
For CloudEngine 7800 version V200R019C10SPC800, update to a fixed version to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable products until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Huawei Vrp