CRITICAL · 9.8

CVE-2016-6178

Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devi...

Vulnerability Description

Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiNe5000E Firmwarev800r006c00
HuaweiNe5000E-
HuaweiCloudengine 12800 Firmwarev100r003c00
HuaweiCloudengine 12800-
HuaweiPtn 6900-2-M8 Firmwarev800r007c00
HuaweiPtn 6900-2-M8-
HuaweiCx600 Firmwarev600r008c20
HuaweiCx600-
HuaweiNe40E Firmwarev600r008c20
HuaweiNe40E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6178?

CVE-2016-6178 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devi...

How severe is CVE-2016-6178?

CVE-2016-6178 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-6178?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ne5000E Firmware, Huawei Ne5000E, Huawei Cloudengine 12800 Firmware, Huawei Cloudengine 12800, Huawei Ptn 6900-2-M8 Firmware.