Buffer Overflow Vulnerability in Huawei Video Conferencing Products
CVE-2017-15355

5.3MEDIUM

Key Information:

Vendor

McAfee

Vendor
CVE Published:
15 February 2018

What is CVE-2017-15355?

Huawei's video conferencing products, including the DP300 and V500R002C00, are susceptible to a buffer overflow vulnerability due to inadequate input validation of specific parameters in HTTP messages. An attacker can exploit this flaw by sending specially crafted requests, potentially leading to abnormal service behavior and disruption in operations.

Affected Version(s)

DP300,RP200,TE30,TE40,TE50,TE60,TX50 DP300 ,V500R002C00 ,RP200 ,V600R006C00 ,TE30 ,V100R001C10 ,V500R002C00 ,V600R006C00 ,TE40 ,V500R002C00 ,V600R006C00 ,TE50 ,V500R002C00 ,V600R006C00 ,TE60 ,V100R001C10 ,V500R002C00 ,V600R006C00 ,TX50 ,V500R002C00 ,V600R006C00

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.