Integer Overflow Vulnerability in Huawei Networking Device Software
CVE-2017-15344

7.5HIGH

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
15 February 2018

Summary

The AR3200 series from Huawei is impacted by an integer overflow vulnerability due to insufficient validation of certain fields within SCTP messages. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted SCTP message, leading to a potential system reboot. This loophole underscores the necessity for proper validation processes to safeguard against unauthorized intrusions and service disruptions.

Affected Version(s)

AR3200 V200R006C10,V200R006C11,V200R007C00,V200R007C01,V200R007C02,V200R008C00,V200R008C10,V200R008C20,V200R008C30

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.