HIGH · 8.1

CVE-2016-5234

Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, ...

Vulnerability Description

Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiRse6500-
HuaweiRse6500 Firmwarev100r001c00
HuaweiVp9600 Series Firmwarev200r001c01
HuaweiVp9630-
HuaweiVp9650-
HuaweiVp9660-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-5234?

CVE-2016-5234 is a vulnerability with a CVSS score of 8.1 (HIGH). Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, ...

How severe is CVE-2016-5234?

CVE-2016-5234 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-5234?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Rse6500, Huawei Rse6500 Firmware, Huawei Vp9600 Series Firmware, Huawei Vp9630, Huawei Vp9650.