QID 43588

Date Published: 2023-04-26

QID 43588: Huawei Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (huawei-sa-20160706-01-openssl)

Huawei Technologies offers a variety of network technologies and solutions to help telecommunications operators expand the capacity of their mobile broadband networks

Multiple Vulnerabilities are detected in huawei products. CVE-2016-2108 : OpenSSL Untrusted ASN.1 Structures Out-of-Bounds Write Vulnerability.
CVE-2016-2107 : OpenSSL AES CBC Cipher Man-in-the-Middle Vulnerability.
CVE-2016-2106 : OpenSSL EVP_EncryptUpdate Function Overflow Heap Corruption Vulnerability.
CVE-2016-2105 : OpenSSL EVP_EncodeUpdate Function Overflow Vulnerability.
CVE-2016-2109 : OpenSSL d2i_CMS_bio Function Denial of Service Vulnerability.
CVE-2016-2176 : OpenSSL ASN.1 Strings X509_NAME_oneline Function Overread Vulnerability.

Affected product:
eSight Network

QID Detection Logic (Authenticated):
This checks for the vulnerable version of Huawei eSight Network.

Successful exploitation of these vulnerabilities will allow remote attacker to execute arbitrary code or cause a denial of service (DoS) condition,attacker can obtain sensitive information.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Huawei has released an advisory detailing various solutions available to fix this issue. Refer to Huawei Security Advisory huawei-sa-20160706-01-openssl-en for additional information on obtaining the fixes.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20160706-01-openssl-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20160706-01-openssl-en