Vulnerability Description
Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, TP3206 V100R002C00, VP9660 V500R002C00, V500R002C10 have a resource exhaustion vulnerability. The software does not process certain field of H.323 message properly, a remote unauthenticated attacker could send crafted H.323 message to the device, successful exploit could cause certain service unavailable since the stack memory is exhausted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Dp300 Firmware | v500r002c00 |
| Huawei | Dp300 | - |
| Huawei | Secospace Usg6300 Firmware | v500r001c00 |
| Huawei | Secospace Usg6300 | - |
| Huawei | Secospace Usg6500 Firmware | v500r001c00 |
| Huawei | Secospace Usg6500 | - |
| Huawei | Secospace Usg6600 Firmware | v500r001c00 |
| Huawei | Secospace Usg6600 | - |
| Huawei | Tp3206 Firmware | v100r002c00 |
| Huawei | Tp3206 | - |
| Huawei | Vp9660 Firmware | v500r002c00 |
| Huawei | Vp9660 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171213-02-h3Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171213-02-h3Vendor Advisory
FAQ
What is CVE-2017-17166?
CVE-2017-17166 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V50...
How severe is CVE-2017-17166?
CVE-2017-17166 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17166?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Dp300 Firmware, Huawei Dp300, Huawei Secospace Usg6300 Firmware, Huawei Secospace Usg6300, Huawei Secospace Usg6500 Firmware.