CVE-2016-4577

HIGH

Huawei USG9500 NGFW Module Secospace USG6300 USG6500 USG6600 - Buffer Overflow via Smart DNS Crafted Packet

Title source: llm
STIX 2.1

Description

Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/90532

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 31.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (5)
huawei/ngfw_module_firmware v500r001c00
huawei/secospace_usg6300_firmware v500r001c00
huawei/secospace_usg6500_firmware v500r001c00
huawei/secospace_usg6600_firmware v500r001c00
huawei/usg9500_firmware v500r001c00
Published May 23, 2016
Tracked Since Feb 18, 2026