7.8

CVE-2017-17312

Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products. Due to improper handling of the malformed messages, an attacker may sent crafted packets to the affected device to exploit these vulnerabilities. Successful exploit the vulnerability could lead to device deny of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Usg2205bsr Firmware Version v300r001c10spc600
   Huawei ≫ Usg2205bsr Version -
Huawei ≫ Usg2220bsr Firmware Version v300r001c00
   Huawei ≫ Usg2220bsr Version -
Huawei ≫ Usg5120bsr Firmware Version v300r001c00
   Huawei ≫ Usg5120bsr Version -
Huawei ≫ Usg5150bsr Firmware Version v300r001c00
   Huawei ≫ Usg5150bsr Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.608
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180813-01-Bleichenbacher-en
Vendor Advisory