CVE-2016-8790
Summary
| CVE | CVE-2016-8790 |
|---|---|
| State | PUBLISHED |
| Assigner | huawei |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-02 20:59:01 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 with software before V200R001C00SPC700 could allow the attacker to exploit a buffer overflow vulnerability by sending crafted packets to the affected system to cause a main control board reboot. |
Risk And Classification
Primary CVSS: v3.0 5.7 MEDIUM from [email protected]
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-119 | Buffer Overflow
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.7 | MEDIUM | CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5.5 | AV:A/AC:L/Au:S/C:N/I:N/A:C |
CVSS v3.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:A/AC:L/Au:S/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Cloudengine 12800 | - | All | All | All |
| Operating System | Huawei | Cloudengine 12800 Firmware | v100r003c10 | All | All | All |
| Operating System | Huawei | Cloudengine 12800 Firmware | v100r005c00 | All | All | All |
| Operating System | Huawei | Cloudengine 12800 Firmware | v100r005c10 | All | All | All |
| Operating System | Huawei | Cloudengine 12800 Firmware | v100r006c00 | All | All | All |
| Hardware | Huawei | Cloudengine 5800 | - | All | All | All |
| Operating System | Huawei | Cloudengine 5800 Firmware | v100r003c10 | All | All | All |
| Operating System | Huawei | Cloudengine 5800 Firmware | v100r005c00 | All | All | All |
| Operating System | Huawei | Cloudengine 5800 Firmware | v100r005c10 | All | All | All |
| Operating System | Huawei | Cloudengine 5800 Firmware | v100r006c00 | All | All | All |
| Hardware | Huawei | Cloudengine 6800 | - | All | All | All |
| Operating System | Huawei | Cloudengine 6800 Firmware | v100r003c10 | All | All | All |
| Operating System | Huawei | Cloudengine 6800 Firmware | v100r005c00 | All | All | All |
| Operating System | Huawei | Cloudengine 6800 Firmware | v100r005c10 | All | All | All |
| Operating System | Huawei | Cloudengine 6800 Firmware | v100r006c00 | All | All | All |
| Hardware | Huawei | Cloudengine 7800 | - | All | All | All |
| Operating System | Huawei | Cloudengine 7800 Firmware | v100r003c10 | All | All | All |
| Operating System | Huawei | Cloudengine 7800 Firmware | v100r005c00 | All | All | All |
| Operating System | Huawei | Cloudengine 7800 Firmware | v100r005c10 | All | All | All |
| Operating System | Huawei | Cloudengine 7800 Firmware | v100r006c00 | All | All | All |
| Hardware | Huawei | Cloudengine 8800 | - | All | All | All |
| Operating System | Huawei | Cloudengine 8800 Firmware | v100r006c00 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | CloudEngine 5800CloudEngine 6800CloudEngine 7800CloudEngine 8800CloudEngine 12800 V100R003C10V100R005C00V100R005C10V100R006C00 | affected CloudEngine 5800,CloudEngine 6800,CloudEngine 7800,CloudEngine 8800,CloudEngine 12800 V100R003C10,V100R005C00,V100R005C10,V100R006C00 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Huawei CloudEngine Products CVE-2016-8790 Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Advisory - Buffer Overflow Vulnerability in Some Huawei Products | af854a3a-2127-422b-91ae-364da2661108 | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.