QID 43891

Date Published: 2021-10-27

QID 43891: Huawei Router Multiple Vulnerabilities (Huawei-SA-20171215-01-buffer-en)

There are two buffer overflow vulnerabilities in some Huawei products. An unauthenticated, remote attacker may send specially crafted SIP packages to the affected products. Due to the insufficient validation of some values for SIP packages, successful exploit may cause services abnormal. (Vulnerability ID: HWPSIRT-2017-04098 and HWPSIRT-2017-04100)
The two vulnerabilities have been assigned two Common Vulnerabilities and Exposures (CVE) IDs: CVE-2017-17295 and CVE-2017-17297.

There is a memory leak vulnerability in some Huawei products. An unauthenticated, remote attacker may send specially crafted H323 packages to the affected products. Due to not release the allocated memory properly to handle the packets, successful exploit may cause memory leak and some services abnormal. (Vulnerability ID: HWPSIRT-2017-04099)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-17296.

Successful exploit may cause memory leak and some services abnormal.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20171215-01-buffer-en for updates and patch information.
    Vendor References

    CVEs related to QID 43891

    Software Advisories
    Advisory ID Software Component Link
    Huawei-SA-20171215-01-buffer-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20171215-01-buffer-en