Integer Overflow Vulnerability in Huawei AR3200 Devices
CVE-2017-15343

7.5HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
15 February 2018

Summary

The Huawei AR3200 devices exhibit an integer overflow vulnerability due to insufficient validation of fields in SCTP messages. An unauthenticated remote attacker could exploit this weakness by sending crafted SCTP messages, potentially leading to unexpected system reboots. Users of affected software versions should prioritize updating their systems to mitigate the associated risks.

Affected Version(s)

AR3200 V200R006C10,V200R006C11,V200R007C00,V200R007C01,V200R007C02,V200R008C00,V200R008C10,V200R008C20,V200R008C30

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.