5.5

CVE-2017-15314

Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE50 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability due to memory don't be released when the XML parser process some node fail. An attacker could exploit it to cause memory leak, which may further lead to system exceptions.

Data is provided by the National Vulnerability Database (NVD)
HuaweiDp300 Firmware Versionv500r002c00
   HuaweiDp300 Version-
HuaweiRp200 Firmware Versionv500r002c00spc200
   HuaweiRp200 Version-
HuaweiRp200 Firmware Versionv600r006c00
   HuaweiRp200 Version-
HuaweiTe30 Firmware Versionv100r001c10spc300
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv100r001c10spc500
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv100r001c10spc600
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv100r001c10spc700
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spc200
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spc500
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spc600
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spc700
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spc900
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv500r002c00spcb00
   HuaweiTe30 Version-
HuaweiTe30 Firmware Versionv600r006c00
   HuaweiTe30 Version-
HuaweiTe40 Firmware Versionv500r002c00spc600
   HuaweiTe40 Version-
HuaweiTe40 Firmware Versionv500r002c00spc700
   HuaweiTe40 Version-
HuaweiTe40 Firmware Versionv500r002c00spc900
   HuaweiTe40 Version-
HuaweiTe40 Firmware Versionv500r002c00spcb00
   HuaweiTe40 Version-
HuaweiTe40 Firmware Versionv600r006c00
   HuaweiTe40 Version-
HuaweiTe50 Firmware Versionv500r002c00spc600
   HuaweiTe50 Version-
HuaweiTe50 Firmware Versionv500r002c00spc700
   HuaweiTe50 Version-
HuaweiTe50 Firmware Versionv500r002c00spcb00
   HuaweiTe50 Version-
HuaweiTe50 Firmware Versionv600r006c00
   HuaweiTe50 Version-
HuaweiTe60 Firmware Versionv100r001c10
   HuaweiTe60 Version-
HuaweiTe60 Firmware Versionv500r002c00
   HuaweiTe60 Version-
HuaweiTe60 Firmware Versionv600r006c00
   HuaweiTe60 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.02% 0.036
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.