ID

VAR-201804-0446


CVE

CVE-2017-17318


TITLE

Huawei MBB E5771h-937 Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-013360

DESCRIPTION

Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http request to device, the webserver process will try to apply too much memory which can cause the device to become unable to respond. An attacker can launch a DoS attack by exploiting this vulnerability. HuaweiE5771h-937 is a portable wireless router from China's Huawei company

Trust: 2.16

sources: NVD: CVE-2017-17318 // JVNDB: JVNDB-2017-013360 // CNVD: CNVD-2018-08877

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-08877

AFFECTED PRODUCTS

vendor:huaweimodel:e5771h-937scope:ltversion:v200r001b329d05sp00c1308

Trust: 1.0

vendor:huaweimodel:e5771h-937scope:ltversion:v200r001b328d62sp00c1133

Trust: 1.0

vendor:huaweimodel:e5771h-937scope:ltversion:e5771h-937tcpu-v200r001b328d62sp00c1133

Trust: 0.8

vendor:huaweimodel:e5771h-937scope:ltversion:e5771h-937tcpu-v200r001b329d05sp00c1308

Trust: 0.8

vendor:huaweimodel:e5771h-937 <e5771h-937tcpu-v200r001b328d62sp00c1133scope: - version: -

Trust: 0.6

vendor:huaweimodel:e5771h-937 <e5771h-937tcpu-v200r001b329d05sp00c1308scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-08877 // JVNDB: JVNDB-2017-013360 // NVD: CVE-2017-17318

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-17318
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-17318
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2018-08877
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201805-045
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2017-17318
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-08877
severity: MEDIUM
baseScore: 6.1
vectorString: AV:A/AC:L/AU:N/C:N/I:N/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2017-17318
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-08877 // JVNDB: JVNDB-2017-013360 // CNNVD: CNNVD-201805-045 // NVD: CVE-2017-17318

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2017-013360 // NVD: CVE-2017-17318

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201805-045

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201805-045

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-013360

PATCH

title:huawei-sa-20180428-01-mbburl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180428-01-mbb-en

Trust: 0.8

title:HuaweiE5771h-937 patch for denial of service vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/128081

Trust: 0.6

title:Huawei E5771h-937 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=79788

Trust: 0.6

sources: CNVD: CNVD-2018-08877 // JVNDB: JVNDB-2017-013360 // CNNVD: CNNVD-201805-045

EXTERNAL IDS

db:NVDid:CVE-2017-17318

Trust: 3.0

db:JVNDBid:JVNDB-2017-013360

Trust: 0.8

db:CNVDid:CNVD-2018-08877

Trust: 0.6

db:CNNVDid:CNNVD-201805-045

Trust: 0.6

sources: CNVD: CNVD-2018-08877 // JVNDB: JVNDB-2017-013360 // CNNVD: CNNVD-201805-045 // NVD: CVE-2017-17318

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180428-01-mbb-en

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-17318

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-17318

Trust: 0.8

url:http://www.huawei.com/cn/psirt/security-advisories/2018/huawei-sa-20180428-01-mbb-cn

Trust: 0.6

sources: CNVD: CNVD-2018-08877 // JVNDB: JVNDB-2017-013360 // CNNVD: CNNVD-201805-045 // NVD: CVE-2017-17318

SOURCES

db:CNVDid:CNVD-2018-08877
db:JVNDBid:JVNDB-2017-013360
db:CNNVDid:CNNVD-201805-045
db:NVDid:CVE-2017-17318

LAST UPDATE DATE

2024-11-23T22:26:25.515000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-08877date:2018-05-04T00:00:00
db:JVNDBid:JVNDB-2017-013360date:2018-06-25T00:00:00
db:CNNVDid:CNNVD-201805-045date:2018-05-02T00:00:00
db:NVDid:CVE-2017-17318date:2024-11-21T03:17:49.640

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-08877date:2018-05-04T00:00:00
db:JVNDBid:JVNDB-2017-013360date:2018-06-25T00:00:00
db:CNNVDid:CNNVD-201805-045date:2018-05-02T00:00:00
db:NVDid:CVE-2017-17318date:2018-04-30T14:29:00.267