ID

VAR-201406-0505


TITLE

Multiple Huawei product 'eSap' platform remote heap buffer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2014-03840

DESCRIPTION

Huawei is a private technology company headquartered in Shenzhen, Guangdong Province, China, which manufactures and sells telecom equipment. It was founded in 1987 by Ren Zhengfei in Shenzhen, China. It is the world's largest provider of telecommunications network solutions and the second largest telecommunications network in the world. Base station equipment supplier. Multiple Huawei products have multiple heap buffer overflow vulnerabilities in their implementation due to failure to properly restrict access to heap memory. Attackers can exploit these vulnerabilities to cause a denial of service

Trust: 0.81

sources: CNVD: CNVD-2014-03840 // BID: 68130

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03840

AFFECTED PRODUCTS

vendor:huaweimodel:ethernet switchesscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-03840

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-03840
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2014-03840
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-03840

THREAT TYPE

network

Trust: 0.3

sources: BID: 68130

TYPE

Boundary Condition Error

Trust: 0.3

sources: BID: 68130

PATCH

title:Patch for multiple Huawei product 'eSap' platform remote heap buffer overflow vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/46663

Trust: 0.6

sources: CNVD: CNVD-2014-03840

EXTERNAL IDS

db:BIDid:68130

Trust: 0.9

db:CNVDid:CNVD-2014-03840

Trust: 0.6

sources: CNVD: CNVD-2014-03840 // BID: 68130

REFERENCES

url:http://www.securityfocus.com/bid/68130

Trust: 0.6

url:http://www.huawei.com/

Trust: 0.3

sources: CNVD: CNVD-2014-03840 // BID: 68130

CREDITS

The vendor reported these issues.

Trust: 0.3

sources: BID: 68130

SOURCES

db:CNVDid:CNVD-2014-03840
db:BIDid:68130

LAST UPDATE DATE

2022-05-17T02:09:49.609000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03840date:2014-06-24T00:00:00
db:BIDid:68130date:2014-06-16T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03840date:2014-06-24T00:00:00
db:BIDid:68130date:2014-06-16T00:00:00