Description
Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C00, TE60, V100R001C01, V100R001C10, V500R002C00, V600R006C00, TX50, V500R002C00, V600R006C00, VP9660, V500R002C00, V500R002C10, ViewPoint 8660, V100R008C03, ViewPoint 9030, V100R011C02, V100R011C03, Viewpoint 8660, V100R008C03 have an out-of-bounds read vulnerability. An attacker has to control the peer device and send specially crafted messages to the affected products. Due to insufficient input validation, successful exploit may cause some service abnormal.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171115-01-h323-en
Scores
CVSS v3
3.7
EPSS
0.0018
EPSS Percentile
38.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-125
Status
published
Products (23)
huawei/dp300_firmware
v500r002c00
huawei/rp200_firmware
v500r002c00
huawei/rp200_firmware
v600r006c00
huawei/rse6500_firmware
v500r002c00
huawei/te30_firmware
v100r001c02
huawei/te30_firmware
v100r001c10
huawei/te30_firmware
v500r002c00
huawei/te30_firmware
v600r006c00
huawei/te40_firmware
v500r002c00
huawei/te40_firmware
v600r006c00
... and 13 more
Published
Feb 15, 2018
Tracked Since
Feb 18, 2026