HIGH · 7.5

CVE-2017-17165

IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00,...

Vulnerability Description

IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S2700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5300 V200R003C00, V200R003C00SPC300T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R005C05, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5700 V200R003C00, V200R003C00SPC316T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S600-E V200R008C00, V200R009C00, S6300 V200R003C00, V200R005C00, V200R007C00, V200R008C00, V200R009C00, S6700 V200R003C00, V200R005C00, V200R005C01, V200R005C02, V200R007C00, V200R008C00, V200R009C00 has an out-of-bounds read vulnerability. An unauthenticated attacker may send crafted malformed IPv6 packets to the affected products. Due to insufficient verification of the packets, successful exploit will cause device to reset.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiQuidway S2700 Firmwarev200r003c00spc300
HuaweiQuidway S2700-
HuaweiQuidway S5300 Firmwarev200r003c00spc300
HuaweiQuidway S5300-
HuaweiQuidway S5700 Firmwarev200r003c00spc300
HuaweiQuidway S5700-
HuaweiS2300 Firmwarev200r003c00
HuaweiS2300-
HuaweiS2700 Firmwarev200r005c00
HuaweiS2700-
HuaweiS5300 Firmwarev200r003c00
HuaweiS5300-
HuaweiS5700 Firmwarev200r003c00
HuaweiS5700-
HuaweiS600-E Firmwarev200r008c00
HuaweiS600-E-
HuaweiS6300 Firmwarev200r003c00
HuaweiS6300-
HuaweiS6700 Firmwarev200r003c00
HuaweiS6700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-17165?

CVE-2017-17165 is a vulnerability with a CVSS score of 7.5 (HIGH). IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00,...

How severe is CVE-2017-17165?

CVE-2017-17165 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-17165?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Quidway S2700 Firmware, Huawei Quidway S2700, Huawei Quidway S5300 Firmware, Huawei Quidway S5300, Huawei Quidway S5700 Firmware.