HIGH · 7.5

CVE-2016-4577

Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers t...

Vulnerability Description

Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."

CVSS Score

7.5

HIGH

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiUsg9500-
HuaweiUsg9500 Firmwarev500r001c00
HuaweiNgfw Module-
HuaweiNgfw Module Firmwarev500r001c00
HuaweiSecospace Usg6300-
HuaweiSecospace Usg6300 Firmwarev500r001c00
HuaweiSecospace Usg6600-
HuaweiSecospace Usg6600 Firmwarev500r001c00
HuaweiSecospace Usg6500-
HuaweiSecospace Usg6500 Firmwarev500r001c00

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-4577?

CVE-2016-4577 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers t...

How severe is CVE-2016-4577?

CVE-2016-4577 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-4577?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Usg9500, Huawei Usg9500 Firmware, Huawei Ngfw Module, Huawei Ngfw Module Firmware, Huawei Secospace Usg6300.