huawei.comConfirmation
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-01-vpp-en CVE-2017-17150
MEDIUM
Record summary
CVE-2017-17150 has a selected CVSS score of 5.5 (medium).
Description
Timergrp module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an DoS vulnerability due to insufficient validation of the parameter. An authenticated local attacker may call a special API with special parameter, which cause an infinite loop. Successful exploit of this vulnerability can allow an attacker to launch DOS attack.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DP300; RP200; TE30; TE40; TE50; TE60Browse Huawei Technologies Co., Ltd. / DP300; RP200; TE30; TE40; TE50; TE60 | CVE List | DP300 V500R002C00 | affected |
| RP200 V500R002C00 | affected | ||
| V600R006C00 | affected | ||
| TE30 V100R001C10 | affected | ||
| V500R002C00 | affected | ||
| TE40 V500R002C00 | affected | ||
| TE50 V500R002C00 | affected | ||
| TE60 V100R001C10 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-17150