Vulnerability Description
Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets, this could be exploited to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Espace 7950 Firmware | v200r003c30 |
| Huawei | Espace 7950 | - |
| Huawei | Espace 8950 Firmware | v200r003c00 |
| Huawei | Espace 8950 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-01-esVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180131-01-esVendor Advisory
FAQ
What is CVE-2017-17221?
CVE-2017-17221 is a vulnerability with a CVSS score of 8.8 (HIGH). Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the ...
How severe is CVE-2017-17221?
CVE-2017-17221 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17221?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Espace 7950 Firmware, Huawei Espace 7950, Huawei Espace 8950 Firmware, Huawei Espace 8950.