Memory leak in Huawei products - CVE-2021-40008

 

Memory leak in Huawei products - CVE-2021-40008

Published: December 9, 2021


Vulnerability identifier: #VU58750
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40008
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak while parse a series of crafted binary messages. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

Huawei CloudEngine 12800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800

How to mitigate CVE-2021-40008

Install updates from vendor's website.

Huawei CloudEngine 12800 - update to V200R019SPH002
Huawei CloudEngine 5800 - update to V200R019SPH002
Huawei CloudEngine 6800 - update to V200R019SPH002
Huawei CloudEngine 7800 - update to V200R019SPH002

External References

Related Security Bulletins