Denial of service in Huawei products - CVE-2016-8277

 

Denial of service in Huawei products - CVE-2016-8277

Published: October 4, 2016 / Updated: October 4, 2016


Vulnerability identifier: #VU729
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8277
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to cause denial of service on the target system.
The weakness exists due to insufficient input verification. Via an unspecified command parameter attackers can trigger the service deny.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Huawei USG5500
Huawei USG5100
Huawei USG2200
Huawei USG2100

How to mitigate CVE-2016-8277

Update to V300R001C10SPC600.


External References

Related Security Bulletins