Vulnerability Description
Huawei DP300 V500R002C00, TE60 V600R006C00, TP3106 V100R002C00, eSpace U1981 V200R003C30SPC100 have a denial of service vulnerability. The software does not correctly calculate the rest size in a buffer when handling SSL connections. A remote unauthenticated attacker could send a lot of crafted SSL messages to the device, successful exploit could cause no space in the buffer and then denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Dp300 Firmware | v500r002c00 |
| Huawei | Dp300 | - |
| Huawei | Te60 Firmware | v600r006c00 |
| Huawei | Te60 | - |
| Huawei | Tp3106 Firmware | v100r002c00 |
| Huawei | Tp3106 | - |
| Huawei | Espace U1981 Firmware | v200r003c30spc100 |
| Huawei | Espace U1981 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-ssl-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-ssl-enVendor Advisory
FAQ
What is CVE-2017-15342?
CVE-2017-15342 is a vulnerability with a CVSS score of 7.5 (HIGH). Huawei DP300 V500R002C00, TE60 V600R006C00, TP3106 V100R002C00, eSpace U1981 V200R003C30SPC100 have a denial of service vulnerability. The software does not correctly calculate the rest size in a buff...
How severe is CVE-2017-15342?
CVE-2017-15342 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15342?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Dp300 Firmware, Huawei Dp300, Huawei Te60 Firmware, Huawei Te60, Huawei Tp3106 Firmware.