CVE-2017-15314

MEDIUM

Huawei Dp300 Firmware - Resource Leak

Title source: rule
STIX 2.1

Description

Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE50 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerability due to memory don't be released when the XML parser process some node fail. An attacker could exploit it to cause memory leak, which may further lead to system exceptions.

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-772
Status published
Products (26)
huawei/dp300_firmware v500r002c00
huawei/rp200_firmware v500r002c00spc200
huawei/rp200_firmware v600r006c00
huawei/te30_firmware v100r001c10spc300
huawei/te30_firmware v100r001c10spc500
huawei/te30_firmware v100r001c10spc600
huawei/te30_firmware v100r001c10spc700
huawei/te30_firmware v500r002c00spc200
huawei/te30_firmware v500r002c00spc500
huawei/te30_firmware v500r002c00spc600
... and 16 more
Published Mar 09, 2018
Tracked Since Feb 18, 2026