Improper Resource Management in Huawei AR Series Devices
CVE-2018-7920

7.5HIGH

Key Information:

Vendor
McAfee
Vendor
CVE Published:
19 April 2018

Summary

Huawei's AR1200, AR160, AR200, AR2200, and AR3200 devices are susceptible to a vulnerability stemming from an improper implementation of the Access Control List (ACL) mechanism. This security flaw can be exploited by remote attackers who send specially crafted TCP messages to the devices' management interface. The exploitation leads to a depletion of socket resources, which can cause a Denial of Service (DoS) situation, rendering the management interface unresponsive. Protecting these devices from such attacks is crucial to maintaining network integrity and uptime.

Affected Version(s)

AR1200, AR160, AR200, AR2200, AR3200 V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300, V200R006C10SPC300

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.