Vulnerability Description
Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C00, TE60, V100R001C01, V100R001C10, V500R002C00, V600R006C00, TX50, V500R002C00, V600R006C00, VP9660, V500R002C00, V500R002C10, ViewPoint 8660, V100R008C03, ViewPoint 9030, V100R011C02, V100R011C03, Viewpoint 8660, V100R008C03 have an out-of-bounds read vulnerability. An attacker has to control the peer device and send specially crafted messages to the affected products. Due to insufficient input validation, successful exploit may cause some service abnormal.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Dp300 Firmware | v500r002c00 |
| Huawei | Dp300 | - |
| Huawei | Rp200 Firmware | v500r002c00 |
| Huawei | Rp200 | - |
| Huawei | Rse6500 Firmware | v500r002c00 |
| Huawei | Rse6500 | - |
| Huawei | Te30 Firmware | v100r001c02 |
| Huawei | Te30 | - |
| Huawei | Te40 Firmware | v500r002c00 |
| Huawei | Te40 | - |
| Huawei | Te50 Firmware | v500r002c00 |
| Huawei | Te50 | - |
| Huawei | Te60 Firmware | v100r001c01 |
| Huawei | Te60 | - |
| Huawei | Tx50 Firmware | v500r002c00 |
| Huawei | Tx50 | - |
| Huawei | Viewpoint 8660 Firmware | v100r008c03 |
| Huawei | Viewpoint 8660 | - |
| Huawei | Vp9660 Firmware | v500r002c00 |
| Huawei | Vp9660 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171115-01-h323-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171115-01-h323-enVendor Advisory
FAQ
What is CVE-2017-15353?
CVE-2017-15353 is a vulnerability with a CVSS score of 3.7 (LOW). Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C...
How severe is CVE-2017-15353?
CVE-2017-15353 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15353?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Dp300 Firmware, Huawei Dp300, Huawei Rp200 Firmware, Huawei Rp200, Huawei Rse6500 Firmware.