7.5
CVSSv3

CVE-2017-15344

Published: 15/02/2018 Updated: 22/02/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei ar1200_firmware v200r007c01

huawei ar120-s_firmware v200r006c10

huawei ar120-s_firmware v200r008c20

huawei ar120-s_firmware v200r008c30

huawei ar3200_firmware v200r008c00

huawei ar3200_firmware v200r008c10

huawei ar1200_firmware v200r007c02

huawei ar3200_firmware v200r006c11

huawei ar120-s_firmware v200r007c00