Vulnerability Description
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR150-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR160 V200R006C10, V200R006C12, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR200 V200R006C10, V200R007C00, V200R007C01, V200R008C20, V200R008C30; AR200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR2200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30; AR510 V200R006C10, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R008C20, V200R008C30; SRG1300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG2300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG3300 V200R006C10, V200R007C00, V200R008C20, V200R008C30 have an input validation vulnerability in Huawei multiple products. Due to the insufficient input validation, an unauthenticated, remote attacker may craft a malformed Stream Control Transmission Protocol (SCTP) packet and send it to the device, causing the device to read out of bounds and restart.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ar120-S Firmware | v200r006c10 |
| Huawei | Ar120-S | - |
| Huawei | Ar1200 Firmware | v200r006c10 |
| Huawei | Ar1200 | - |
| Huawei | Ar1200-S Firmware | v200r006c10 |
| Huawei | Ar1200-S | - |
| Huawei | Ar150 Firmware | v200r006c10 |
| Huawei | Ar150 | - |
| Huawei | Ar150-S Firmware | v200r006c10 |
| Huawei | Ar150-S | - |
| Huawei | Ar160 Firmware | v200r006c10 |
| Huawei | Ar160 | - |
| Huawei | Ar200 Firmware | v200r006c10 |
| Huawei | Ar200 | - |
| Huawei | Ar200-S Firmware | v200r006c10 |
| Huawei | Ar200-S | - |
| Huawei | Ar2200 Firmware | v200r006c10 |
| Huawei | Ar2200 | - |
| Huawei | Ar2200-S Firmware | v200r006c10 |
| Huawei | Ar2200-S | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-sctp-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-sctp-enVendor Advisory
FAQ
What is CVE-2017-15317?
CVE-2017-15317 is a vulnerability with a CVSS score of 7.5 (HIGH). AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R00...
How severe is CVE-2017-15317?
CVE-2017-15317 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15317?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ar120-S Firmware, Huawei Ar120-S, Huawei Ar1200 Firmware, Huawei Ar1200, Huawei Ar1200-S Firmware.