QID 43841
Date Published: 2021-09-13
QID 43841: Huawei Router Stack Overflow Vulnerabilities in SNMPv3 debugging mode Vulnerability (HW-260626)
Huawei has released a security update for Stack Overflow Vulnerabilities in SNMPv3 debugging mode to fix the vulnerability.
Affected Products:
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
When the debugging is turn on, attackers can execute injected arbitrary commands on the device by exploiting the vulnerability.
Solution
Refer to Huawei security advisory HW-260626 for updates and patch information.Workaround:
Connect to the device using SSH and turn off the debugging of SNMPv3. The detailed configuration is as follows(In the case of AR Router): [Quidway]undo debugging snmp-agent header
Connect to the device using SSH and turn off the debugging of SNMPv3. The detailed configuration is as follows(In the case of AR Router): [Quidway]undo debugging snmp-agent header
Vendor References
CVEs related to QID 43841
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| HW-260626 | Huawei VRP |
|