Improper Resource Management in Huawei AR Series Devices
CVE-2018-7920
7.5HIGH
Summary
Huawei's AR1200, AR160, AR200, AR2200, and AR3200 devices are susceptible to a vulnerability stemming from an improper implementation of the Access Control List (ACL) mechanism. This security flaw can be exploited by remote attackers who send specially crafted TCP messages to the devices' management interface. The exploitation leads to a depletion of socket resources, which can cause a Denial of Service (DoS) situation, rendering the management interface unresponsive. Protecting these devices from such attacks is crucial to maintaining network integrity and uptime.
Affected Version(s)
AR1200, AR160, AR200, AR2200, AR3200 V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved