5.5
CVE-2017-17148
- EPSS 0.02%
- Veröffentlicht 09.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:35
- Quelle psirt@huawei.com
- CVE-Watchlists
- Unerledigt
Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is called. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Dp300 Firmware Version <= v500r002c00
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.027 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 4.9 | 3.9 | 6.9 |
AV:L/AC:L/Au:N/C:N/I:N/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.