Vulnerability Description
Memory leak in Huawei S5300EI, S5300SI, S5310HI, S6300EI/ S2350EI, and S5300LI Campus series switches with software V200R001C00 before V200R001SPH018, V200R002C00 before V200R003SPH011, and V200R003C00 before V200R003SPH011; S9300, S7700, and S9700 Campus series switches with software V200R001C00 before V200R001SPH023, V200R002C00 before V200R003SPH011, and V200R003C00 before V200R003SPH011; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote attackers to cause a denial of service (memory consumption and reboot) via a large number of ICMPv6 packets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | S2350Ei Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S2350Ei | - |
| Huawei | S5300Ei Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S5300Ei | - |
| Huawei | S5300Si Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S5300Si | - |
| Huawei | S5310Hi Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S5310Hi | - |
| Huawei | S6300Ei Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S6300Ei | - |
| Huawei | S5300Li Firmware | >= v200r001c00, < v200r001sph018 |
| Huawei | S5300Li | - |
| Huawei | S9300 Firmware | >= v200r001c00, < v200r001sph023 |
| Huawei | S9300 | - |
| Huawei | S7700 Firmware | >= v200r001c00, < v200r001sph023 |
| Huawei | S7700 | - |
| Huawei | S9700 Firmware | >= v200r001c00, < v200r001sph023 |
| Huawei | S9700 | - |
| Huawei | S2300 Firmware | >= v100r006c05, < v100r006sph022 |
| Huawei | S2300 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160113-02-switch-Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160113-02-switch-Vendor Advisory
FAQ
What is CVE-2015-8676?
CVE-2015-8676 is a vulnerability with a CVSS score of 7.5 (HIGH). Memory leak in Huawei S5300EI, S5300SI, S5310HI, S6300EI/ S2350EI, and S5300LI Campus series switches with software V200R001C00 before V200R001SPH018, V200R002C00 before V200R003SPH011, and V200R003C0...
How severe is CVE-2015-8676?
CVE-2015-8676 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8676?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei S2350Ei Firmware, Huawei S2350Ei, Huawei S5300Ei Firmware, Huawei S5300Ei, Huawei S5300Si Firmware.