7.8

CVE-2018-7994

Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HuaweiIps Module Versionv500r001c50
   HuaweiIps Module Version-
HuaweiNgfw Module Versionv500r001c50
   HuaweiNgfw Module Version-
HuaweiNgfw Module Versionv500r002c10
   HuaweiNgfw Module Version-
HuaweiNip6300 Versionv500r001c50
   HuaweiNip6300 Version-
HuaweiNip6600 Versionv500r001c50
   HuaweiNip6600 Version-
HuaweiNip6800 Versionv500r001c50
   HuaweiNip6800 Version-
HuaweiSecospace Usg6600 Versionv500r001c50
   HuaweiSecospace Usg6600 Version-
HuaweiUsg9500 Versionv500r001c50
   HuaweiUsg9500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.485
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-772 Missing Release of Resource after Effective Lifetime

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.