Vulnerability Description
Huawei AR100, AR100-S, AR110-S, AR120, AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR510, DP300, NetEngine16EX, RP200, SRG1300, SRG2300, SRG3300, TE30, TE40, TE50, TE60, TP3106, TP3206, ViewPoint 8660, and ViewPoint 9030 have an insufficient validation vulnerability. Since packet validation is insufficient, an unauthenticated attacker may send special H323 packets to exploit the vulnerability. Successful exploit could allow the attacker to send malicious packets and result in DOS attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ar100 Firmware | v200r008c20spc700 |
| Huawei | Ar100 | - |
| Huawei | Ar100-S Firmware | v200r007c00spca00 |
| Huawei | Ar100-S | - |
| Huawei | Ar110-S Firmware | v200r007c00spc600 |
| Huawei | Ar110-S | - |
| Huawei | Ar120 Firmware | v200r006c10 |
| Huawei | Ar120 | - |
| Huawei | Ar120-S Firmware | v200r006c10 |
| Huawei | Ar120-S | - |
| Huawei | Ar1200 Firmware | v200r006c10 |
| Huawei | Ar1200 | - |
| Huawei | Ar1200-S Firmware | v200r006c10 |
| Huawei | Ar1200-S | - |
| Huawei | Ar150 Firmware | v200r006c10 |
| Huawei | Ar150 | - |
| Huawei | Ar150-S Firmware | v200r006c10spc300 |
| Huawei | Ar150-S | - |
| Huawei | Ar160 Firmware | v200r006c10 |
| Huawei | Ar160 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-h323-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-h323-enVendor Advisory
FAQ
What is CVE-2017-17151?
CVE-2017-17151 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Huawei AR100, AR100-S, AR110-S, AR120, AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR510, DP300, NetEngine16EX, RP200, SRG1300, SRG2300, SRG3300, TE30, ...
How severe is CVE-2017-17151?
CVE-2017-17151 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17151?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ar100 Firmware, Huawei Ar100, Huawei Ar100-S Firmware, Huawei Ar100-S, Huawei Ar110-S Firmware.