Buffer overflow in Huawei products - CVE-2021-37129

 

Buffer overflow in Huawei products - CVE-2021-37129

Published: October 21, 2021


Vulnerability identifier: #VU57581
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37129
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.


Affected software

Huawei S9700
Huawei S2700
Huawei S1700
Huawei S6700
Huawei S7700
USG9500
Huawei S5700
Huawei S12700
Huawei NIP6600
Huawei IPS Module
Huawei NGFW Module

How to mitigate CVE-2021-37129

Install updates from vendor's website.

Huawei S9700 - addressed in versions V200R019C10SPC500+V200R019SPH029, V200R020C10SPC500
Huawei S5700 - update to V200R019C10SPC500+V200R019SPH029
Huawei S2700 - update to V200R019C10SPC500+V200R019SPH029
Huawei S1700 - update to V200R019C10SPC500+V200R019SPH029
Huawei S6700 - update to V200R019C10SPC500+V200R019SPH029
Huawei S12700 - addressed in versions V200R019C10SPC500+V200R019SPH029, V200R020C10SPC500
Huawei S7700 - update to V200R019C10SPC500+V200R019SPH029
USG9500 - update to V500R005C20SPC601
Huawei NIP6600 - update to V500R005C20SPC601
Huawei NGFW Module - update to V500R005C20SPC601
Huawei IPS Module - update to V500R005C20SPC601

External References

Related Security Bulletins