CVE-2017-17134

MEDIUM

Huawei DP300 RP200 TE30 TE40 TE50 TE60 Firmware - Denial of Service via XML Parser Null Pointer Dereference

Title source: llm
STIX 2.1

Description

XML parser in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has a DoS vulnerability. Due to not check the specially XML file enough an authenticated local attacker may craft specific XML files to the affected products and parse this file which cause to null pointer accessing and result in DoS attacks.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (13)
huawei/dp300_firmware v500r002c00
huawei/rp200_firmware v500r002c00spc200
huawei/rp200_firmware v600r006c00
huawei/te30_firmware v100r001c10
huawei/te30_firmware v500r002c00
huawei/te30_firmware v600r006c00
huawei/te40_firmware v500r002c00
huawei/te40_firmware v600r006c00
huawei/te50_firmware v500r002c00
huawei/te50_firmware v600r006c00
... and 3 more
Published Mar 05, 2018
Tracked Since Feb 18, 2026