#VU66900 Input validation error in WS7200-10


Published: 2022-09-01

Vulnerability identifier: #VU66900

Vulnerability risk: Low

CVSSv3.1: 5.5 [CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-46835

CWE-ID: CWE-20

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
WS7200-10
Hardware solutions / Firmware

Vendor: Huawei

Description

The vulnerability allows a remote attacker to compromsie the target system.

The vulnerability exists due to improper ICMP packet processing. A remote user on the local network can use specially crafted ICMP packets and cause packet hijacking.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

WS7200-10: 11.0.2.13


External links
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220831-01-5370a6df-en


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability