5.3
CVE-2017-17166
- EPSS 0.23%
- Veröffentlicht 15.02.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:17:37
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, TP3206 V100R002C00, VP9660 V500R002C00, V500R002C10 have a resource exhaustion vulnerability. The software does not process certain field of H.323 message properly, a remote unauthenticated attacker could send crafted H.323 message to the device, successful exploit could cause certain service unavailable since the stack memory is exhausted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Dp300 Firmware Versionv500r002c00
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c50
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c50
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c50
Huawei ≫ Tp3206 Firmware Versionv100r002c00
Huawei ≫ Vp9660 Firmware Versionv500r002c00
Huawei ≫ Vp9660 Firmware Versionv500r002c10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.427 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.