MEDIUM · 5.3

CVE-2014-8570

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with softw...

Vulnerability Description

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with software V200R002, V200R003, V200R005; S12708, S12712 with software V200R005; 5700HI, 5300HI with software V100R006, V200R001, V200R002, V200R003, V200R005; 5710EI, 5310EI with software V200R002, V200R003, V200R005; 5710HI, 5310HI with software V200R003, V200R005; 6700EI, 6300EI with software V200R005 could cause a leak of IP addresses of devices, related to unintended interface support for VRP MPLS LSP Ping.

CVSS Score

5.3

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HuaweiS9300 Firmwarev100r002
HuaweiS9300-
HuaweiS9303 Firmwarev100r002
HuaweiS9303-
HuaweiS9306 Firmwarev100r002
HuaweiS9306-
HuaweiS9312 Firmwarev100r002
HuaweiS9312-
HuaweiS7700 Firmwarev100r002
HuaweiS7700-
HuaweiS7703 Firmwarev100r002
HuaweiS7703-
HuaweiS7706 Firmwarev100r002
HuaweiS7706-
HuaweiS7712 Firmwarev100r002
HuaweiS7712-
HuaweiS9300E Firmwarev200r001
HuaweiS9300E-
HuaweiS9303E Firmwarev200r001
HuaweiS9303E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8570?

CVE-2014-8570 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with softw...

How severe is CVE-2014-8570?

CVE-2014-8570 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8570?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei S9300 Firmware, Huawei S9300, Huawei S9303 Firmware, Huawei S9303, Huawei S9306 Firmware.