8.1

CVE-2016-4087

Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enabled, allows remote attackers to cause a denial of service or execute arbitrary code via crafted DNS packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ S12700 Firmware Version v200r005c00spc300
   Huawei ≫ S12700 Version -
Huawei ≫ S5700 Firmware Version v200r001c00
   Huawei ≫ S5700 Version -
Huawei ≫ S5700 Firmware Version v200r002c00spc100
   Huawei ≫ S5700 Version -
Huawei ≫ S5700 Firmware Version v200r003c00spc300
   Huawei ≫ S5700 Version -
Huawei ≫ S5700 Firmware Version v200r005c00
   Huawei ≫ S5700 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.47% 0.704
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160427-01-dns-en
Vendor Advisory