7.8

CVE-2017-17312

Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products. Due to improper handling of the malformed messages, an attacker may sent crafted packets to the affected device to exploit these vulnerabilities. Successful exploit the vulnerability could lead to device deny of service.

Data is provided by the National Vulnerability Database (NVD)
HuaweiUsg2205bsr Firmware Versionv300r001c10spc600
   HuaweiUsg2205bsr Version-
HuaweiUsg2220bsr Firmware Versionv300r001c00
   HuaweiUsg2220bsr Version-
HuaweiUsg5120bsr Firmware Versionv300r001c00
   HuaweiUsg5120bsr Version-
HuaweiUsg5150bsr Firmware Versionv300r001c00
   HuaweiUsg5150bsr Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.277
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.