Denial of service in Huawei products - CVE-2016-8278
Published: October 4, 2016 / Updated: October 4, 2016
Vulnerability identifier: #VU728
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2016-8278
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Huawei
Affected software:
Huawei USG5500
Huawei USG5100
Huawei USG2200
Huawei USG2100
Huawei USG5500
Huawei USG5100
Huawei USG2200
Huawei USG2100
Detailed vulnerability description
The vulnerability allows a remote user to cause denial of service on the target system.
The weakness exists due to insufficient input verification. Via an unspecified URL attackers can trigger the service deny.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
The weakness exists due to insufficient input verification. Via an unspecified URL attackers can trigger the service deny.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
How to mitigate CVE-2016-8278
Update to V300R001C10SPC600.