7.5
CVE-2017-15342
- EPSS 0.27%
- Veröffentlicht 15.02.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:30
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Huawei DP300 V500R002C00, TE60 V600R006C00, TP3106 V100R002C00, eSpace U1981 V200R003C30SPC100 have a denial of service vulnerability. The software does not correctly calculate the rest size in a buffer when handling SSL connections. A remote unauthenticated attacker could send a lot of crafted SSL messages to the device, successful exploit could cause no space in the buffer and then denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Dp300 Firmware Versionv500r002c00
Huawei ≫ Te60 Firmware Versionv600r006c00
Huawei ≫ Tp3106 Firmware Versionv100r002c00
Huawei ≫ Espace U1981 Firmware Versionv200r003c30spc100
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.27% | 0.47 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.