CVE-2016-6669

HIGH

Huawei AAA <V300R001C10SPC600 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitrary code by sending a crafted EAP packet.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92441

Scores

CVSS v3 7.5
EPSS 0.0212
EPSS Percentile 84.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (4)
huawei/usg2100_firmware < v300r001c00
huawei/usg2200_firmware < v300r001c00
huawei/usg5100_firmware < v300r001c00
huawei/usg5500_firmware < v300r001c00
Published Sep 22, 2016
Tracked Since Feb 18, 2026