ID

VAR-201612-0632


TITLE

Multiple Huawei switches have a denial of service vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-13285

DESCRIPTION

The Huawei S9700, S5700, S6700, S7700, and S9700 are the switch devices of Huawei (Huawei). A number of Huawei switches have a denial of service vulnerability. Because the device lacks input verification, the remote attacker can exploit the vulnerability to construct a malformed Resource Reservation Protocol (RSVP) packet to the device, causing a small buffer overflow of the device and a probabilistic restart.

Trust: 0.6

sources: CNVD: CNVD-2016-13285

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-13285

AFFECTED PRODUCTS

vendor:huaweimodel:s7700 v200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r001c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r002c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r001c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r002c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r007c00scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-13285

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-13285
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2016-13285
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-13285

PATCH

title:Patches for denial of service vulnerabilities in various Huawei switchesurl:https://www.cnvd.org.cn/patchinfo/show/87053

Trust: 0.6

sources: CNVD: CNVD-2016-13285

EXTERNAL IDS

db:CNVDid:CNVD-2016-13285

Trust: 0.6

sources: CNVD: CNVD-2016-13285

REFERENCES

url:http://www.huawei.com/cn/psirt/security-advisories/2016/huawei-sa-20161228-01-rsvp-cn

Trust: 0.6

sources: CNVD: CNVD-2016-13285

SOURCES

db:CNVDid:CNVD-2016-13285

LAST UPDATE DATE

2022-05-04T10:16:21.788000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-13285date:2016-12-30T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-13285date:2016-12-29T00:00:00