Vulnerability Description
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Nip6300 | - |
| Huawei | Nip6300 Firmware | v500r001c00 |
| Huawei | Secospace Usg6500 | - |
| Huawei | Secospace Usg6500 Firmware | v500r001c00 |
| Huawei | Secospace Antiddos8000 | - |
| Huawei | Secospace Antiddos8000 Firmware | v500r001c00 |
| Huawei | Usg9500 | - |
| Huawei | Usg9500 Firmware | v500r001c00 |
| Huawei | Secospace Usg6300 | - |
| Huawei | Secospace Usg6300 Firmware | v500r001c00 |
| Huawei | Ngfw Module | - |
| Huawei | Ngfw Module Firmware | v500r001c00 |
| Huawei | Secospace Usg6600 | - |
| Huawei | Secospace Usg6600 Firmware | v500r001c00 |
| Huawei | Nip6600 | - |
| Huawei | Nip6600 Firmware | v500r001c00 |
| Huawei | Ips Module | - |
| Huawei | Ips Module Firmware | v500r001c00 |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160511-01-aspf-enVendor Advisory
- http://www.securityfocus.com/bid/90530
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160511-01-aspf-enVendor Advisory
- http://www.securityfocus.com/bid/90530
FAQ
What is CVE-2016-4576?
CVE-2016-4576 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS800...
How severe is CVE-2016-4576?
CVE-2016-4576 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-4576?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Nip6300, Huawei Nip6300 Firmware, Huawei Secospace Usg6500, Huawei Secospace Usg6500 Firmware, Huawei Secospace Antiddos8000.