Vulnerability CVE-2016-8784


Published: 2018-03-09

Description:
Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some parameters in the packet are abnormal, the LDP processing module does not release the memory to handle the packet, resulting in memory leak.

Type:

CWE-399

(Resource Management Errors)

CVSS2 => (AV:A/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.3/10
2.9/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Huawei -> Cloudengine 12800 firmware 

 References:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161221-01-ldp-en
http://www.securityfocus.com/bid/95079

Copyright 2024, cxsecurity.com

 

Back to Top