7.5

CVE-2017-17290

The Light Directory Access Protocol (LDAP) clients of Huawei TE60 with software V600R006C00, ViewPoint 9030 with software V100R011C02, V100R011C03 have a resource management errors vulnerability. An unauthenticated, remote attacker may make the LDAP server not respond to the client's request by controlling the LDAP server. Due to improper management of LDAP connection resource, a successful exploit may cause the connection resource exhausted of the LDAP client.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Te60 Firmware Version v600r006c00
   Huawei ≫ Te60 Version -
Huawei ≫ Viewpoint 9030 Firmware Version v100r011c02
   Huawei ≫ Viewpoint 9030 Version -
Huawei ≫ Viewpoint 9030 Firmware Version v100r011c03
   Huawei ≫ Viewpoint 9030 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.26% 0.664
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171213-01-ldap-en
Vendor Advisory