CVE-2017-17165

HIGH

Huawei Quidway - Info Disclosure

Title source: llm
STIX 2.1

Description

IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R003C00SPC300T, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S2700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5300 V200R003C00, V200R003C00SPC300T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R005C05, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S5700 V200R003C00, V200R003C00SPC316T, V200R003C00SPC600, V200R003C02, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00, V200R009C00, S600-E V200R008C00, V200R009C00, S6300 V200R003C00, V200R005C00, V200R007C00, V200R008C00, V200R009C00, S6700 V200R003C00, V200R005C00, V200R005C01, V200R005C02, V200R007C00, V200R008C00, V200R009C00 has an out-of-bounds read vulnerability. An unauthenticated attacker may send crafted malformed IPv6 packets to the affected products. Due to insufficient verification of the packets, successful exploit will cause device to reset.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (50)
huawei/quidway_s2700_firmware v200r003c00spc300
huawei/quidway_s5300_firmware v200r003c00spc300
huawei/quidway_s5700_firmware v200r003c00spc300
huawei/s2300_firmware v200r003c00
huawei/s2300_firmware v200r003c00spc300t
huawei/s2300_firmware v200r005c00
huawei/s2300_firmware v200r006c00
huawei/s2300_firmware v200r007c00
huawei/s2300_firmware v200r008c00
huawei/s2300_firmware v200r009c00
... and 40 more
Published Feb 15, 2018
Tracked Since Feb 18, 2026