Vulnerability Description
IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S2700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5300 V200R003C00, V200R003C00SPC300T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R005C05, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5700 V200R003C00, V200R003C00SPC316T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S600-E V200R008C00, V200R009C00, S6300 V200R003C00, V200R005C00, V200R007C00, V200R008C00, V200R009C00, S6700 V200R003C00, V200R005C00, V200R005C01, V200R005C02, V200R007C00, V200R008C00, V200R009C00 has an out-of-bounds read vulnerability. An unauthenticated attacker may send crafted malformed IPv6 packets to the affected products. Due to insufficient verification of the packets, successful exploit will cause device to reset.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Quidway S2700 Firmware | v200r003c00spc300 |
| Huawei | Quidway S2700 | - |
| Huawei | Quidway S5300 Firmware | v200r003c00spc300 |
| Huawei | Quidway S5300 | - |
| Huawei | Quidway S5700 Firmware | v200r003c00spc300 |
| Huawei | Quidway S5700 | - |
| Huawei | S2300 Firmware | v200r003c00 |
| Huawei | S2300 | - |
| Huawei | S2700 Firmware | v200r005c00 |
| Huawei | S2700 | - |
| Huawei | S5300 Firmware | v200r003c00 |
| Huawei | S5300 | - |
| Huawei | S5700 Firmware | v200r003c00 |
| Huawei | S5700 | - |
| Huawei | S600-E Firmware | v200r008c00 |
| Huawei | S600-E | - |
| Huawei | S6300 Firmware | v200r003c00 |
| Huawei | S6300 | - |
| Huawei | S6700 Firmware | v200r003c00 |
| Huawei | S6700 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171213-02-ipv6-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171213-02-ipv6-enVendor Advisory
FAQ
What is CVE-2017-17165?
CVE-2017-17165 is a vulnerability with a CVSS score of 7.5 (HIGH). IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00,...
How severe is CVE-2017-17165?
CVE-2017-17165 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17165?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Quidway S2700 Firmware, Huawei Quidway S2700, Huawei Quidway S5300 Firmware, Huawei Quidway S5300, Huawei Quidway S5700 Firmware.