QID 43888

Date Published: 2021-10-27

QID 43888: Huawei Router Open Secure Sockets Layer (OpenSSL) Vulnerability Vulnerability (Huawei-SA-20180613-01-openssl-en)

Constructed ASN.1 types with a recursive definition in some OpenSSL versions could eventually exceed the stack given malicious input with excessive recursion. Successful exploit of this vulnerability may result in a Denial of Service attack. (Vulnerability ID: HWPSIRT-2018-03073)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2018-0739.

Successful exploit could result in a Denial of Service attack.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20180613-01-openssl-en for updates and patch information.
    Vendor References

    CVEs related to QID 43888

    Software Advisories
    Advisory ID Software Component Link
    Huawei-SA-20180613-01-openssl-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20180613-01-openssl-en