ID

VAR-201604-0328


CVE

CVE-2015-8677


TITLE

plural Huawei Service disruption in products (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2015-007108

DESCRIPTION

Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00 before V200R006SPH002; S9300, S7700, and S9700 Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH009, and V200R006C00 before V200R006SPH003; S5720HI and S5720EI Campus series switches with software V200R006C00 before V200R006SPH002; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote authenticated users to cause a denial of service (memory consumption and device restart) by logging in and out of the (1) HTTPS or (2) SFTP server, related to SSL session information. HuaweiS5300EI is a Huawei S series switch product. A number of Huawei products have a memory leak vulnerability in the HTTPS or SFTP server, allowing remote attackers to consume memory and log in and out of the HTTPS or SFTP server for denial of service attacks. Multiple Huawei Switches are prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to cause a memory exhaustion, denying service to legitimate users. The Huawei S5300EI and others are all S-series switch products of China's Huawei (Huawei). Memory leak vulnerabilities exist in several Huawei products. The following products and versions are affected: using V200R003C00 version and V200R005C00 version software Huawei S5300EI , S5300SI , S5310HI , S6300EI ,use V200R003C00 Version, V200R005C00 version and V200R006C00 version software Huawei S2350EI , S5300LI , S9300 , S7700 , S9700 ,use V200R006C00 version software Huawei S5720HI, S5720EI, Huawei S2300, S3300 using V100R006C05 software

Trust: 2.61

sources: NVD: CVE-2015-8677 // JVNDB: JVNDB-2015-007108 // CNVD: CNVD-2016-02289 // BID: 90912 // VULHUB: VHN-86638 // VULMON: CVE-2015-8677

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-02289

AFFECTED PRODUCTS

vendor:huaweimodel:s5310hiscope:gteversion:v200r001c00

Trust: 1.0

vendor:huaweimodel:s5300eiscope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s2350eiscope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s5310hiscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s9700scope:ltversion:v200r005sph009

Trust: 1.0

vendor:huaweimodel:s7700scope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s5300liscope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s5300liscope:ltversion:v200r006sph002

Trust: 1.0

vendor:huaweimodel:s2350eiscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s5300eiscope:ltversion:v200r005sph008

Trust: 1.0

vendor:huaweimodel:s9300scope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s5300liscope:ltversion:v200r005sph008

Trust: 1.0

vendor:huaweimodel:s2300scope:ltversion:v100r006sph022

Trust: 1.0

vendor:huaweimodel:s5310hiscope:gteversion:v200r002c00

Trust: 1.0

vendor:huaweimodel:s5310hiscope:ltversion:v200r001sph018

Trust: 1.0

vendor:huaweimodel:s9700scope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s5300liscope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s5300siscope:gteversion:v200r001c00

Trust: 1.0

vendor:huaweimodel:s9700scope:ltversion:v200r006sph003

Trust: 1.0

vendor:huaweimodel:s5300eiscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s9700scope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s5300liscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s7700scope:ltversion:v200r005sph009

Trust: 1.0

vendor:huaweimodel:s9300scope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s5300siscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s5300siscope:gteversion:v200r002c00

Trust: 1.0

vendor:huaweimodel:s5300eiscope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s2350eiscope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s5720hiscope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s9700scope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s5720hiscope:ltversion:v200r006sph002

Trust: 1.0

vendor:huaweimodel:s6300eiscope:gteversion:v200r001c00

Trust: 1.0

vendor:huaweimodel:s3300scope:gteversion:v100r006c05

Trust: 1.0

vendor:huaweimodel:s7700scope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s6300eiscope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s5300liscope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s5300siscope:ltversion:v200r001sph018

Trust: 1.0

vendor:huaweimodel:s7700scope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s7700scope:ltversion:v200r006sph003

Trust: 1.0

vendor:huaweimodel:s2300scope:gteversion:v100r006c05

Trust: 1.0

vendor:huaweimodel:s6300eiscope:gteversion:v200r002c00

Trust: 1.0

vendor:huaweimodel:s6300eiscope:ltversion:v200r001sph018

Trust: 1.0

vendor:huaweimodel:s9300scope:ltversion:v200r005sph009

Trust: 1.0

vendor:huaweimodel:s9700scope:gteversion:v200r005c00

Trust: 1.0

vendor:huaweimodel:s5720eiscope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s5720eiscope:ltversion:v200r006sph002

Trust: 1.0

vendor:huaweimodel:s7700scope:ltversion:v200r003sph011

Trust: 1.0

vendor:huaweimodel:s9300scope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s2350eiscope:gteversion:v200r006c00

Trust: 1.0

vendor:huaweimodel:s2350eiscope:ltversion:v200r006sph002

Trust: 1.0

vendor:huaweimodel:s3300scope:ltversion:v100r006sph022

Trust: 1.0

vendor:huaweimodel:s2350eiscope:ltversion:v200r005sph008

Trust: 1.0

vendor:huaweimodel:s9300scope:ltversion:v200r006sph003

Trust: 1.0

vendor:huaweimodel:s9300scope:gteversion:v200r003c00

Trust: 1.0

vendor:huaweimodel:s9700scope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s2350eiscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s2350eiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s7700scope:eqversion:v200r005sph009

Trust: 0.8

vendor:huaweimodel:s5310hiscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s2300scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300scope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300siscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s5300siscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300siscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s5310hiscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300liscope: - version: -

Trust: 0.8

vendor:huaweimodel:s5310hiscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s5300liscope:eqversion:v200r006sph002

Trust: 0.8

vendor:huaweimodel:s2350eiscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s9300scope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s9700scope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s6300eiscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s6300eiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s2350eiscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s2350eiscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s5300liscope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s7700scope:eqversion:v200r006sph003

Trust: 0.8

vendor:huaweimodel:s9700scope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s5300eiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300scope:eqversion:v200r005sph009

Trust: 0.8

vendor:huaweimodel:s5720hiscope:eqversion:v200r006sph002

Trust: 0.8

vendor:huaweimodel:s7700scope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s5720eiscope:eqversion:v200r006sph002

Trust: 0.8

vendor:huaweimodel:s3300scope:eqversion:v100r006sph022

Trust: 0.8

vendor:huaweimodel:s5300liscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s5300eiscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s3300scope:ltversion:v100r006c05

Trust: 0.8

vendor:huaweimodel:s6300eiscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s7700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5720eiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s2350eiscope:eqversion:v200r006sph002

Trust: 0.8

vendor:huaweimodel:s9700scope:eqversion:v200r005sph009

Trust: 0.8

vendor:huaweimodel:s6300eiscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s3300scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5720eiscope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s9300scope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s5310hiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300scope:eqversion:v200r006sph003

Trust: 0.8

vendor:huaweimodel:s5720hiscope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s6300eiscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s7700scope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s2300scope:eqversion:v100r006sph022

Trust: 0.8

vendor:huaweimodel:s9300scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5300eiscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s5300liscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300eiscope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300eiscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s2300scope:ltversion:v100r006c05

Trust: 0.8

vendor:huaweimodel:s9700scope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s9700scope:eqversion:v200r006sph003

Trust: 0.8

vendor:huaweimodel:s2350eiscope:ltversion:v200r006c00

Trust: 0.8

vendor:huaweimodel:s7700scope:ltversion:v200r003c00

Trust: 0.8

vendor:huaweimodel:s5300liscope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s7700scope:eqversion:v200r003sph011

Trust: 0.8

vendor:huaweimodel:s5300liscope:eqversion:v200r005sph008

Trust: 0.8

vendor:huaweimodel:s9300scope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s9700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5720hiscope: - version: -

Trust: 0.8

vendor:huaweimodel:s5300siscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s5310hiscope:ltversion:v200r005c00

Trust: 0.8

vendor:huaweimodel:s5300siscope: - version: -

Trust: 0.8

vendor:huaweimodel:s5300ei v200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300ei v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300si v200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300si v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5310hi 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5310hi 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6300ei 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6300ei 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2350ei 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2350ei 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2350ei 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300li 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300li 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5300li 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 200r003c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5720hi 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5720ei 200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2300 100r006c05scope: - version: -

Trust: 0.6

vendor:huaweimodel:s3300 100r006c05scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700scope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s9300scope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s2350eiscope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s5720eiscope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s7700scope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s5300liscope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s5720hiscope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s2300scope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s3300scope:eqversion: -

Trust: 0.6

vendor:huaweimodel:s6300eiscope:eqversion: -

Trust: 0.6

sources: CNVD: CNVD-2016-02289 // JVNDB: JVNDB-2015-007108 // CNNVD: CNNVD-201604-314 // NVD: CVE-2015-8677

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-8677
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-8677
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2016-02289
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201604-314
value: MEDIUM

Trust: 0.6

VULHUB: VHN-86638
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-8677
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-8677
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2016-02289
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-86638
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-8677
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2016-02289 // VULHUB: VHN-86638 // VULMON: CVE-2015-8677 // JVNDB: JVNDB-2015-007108 // CNNVD: CNNVD-201604-314 // NVD: CVE-2015-8677

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-86638 // JVNDB: JVNDB-2015-007108 // NVD: CVE-2015-8677

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201604-314

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201604-314

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007108

PATCH

title:Huawei-SA-20160113-03-Switchurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160113-03-switch-en

Trust: 0.8

title:Patches for various Huawei product switch memory leak vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/74355

Trust: 0.6

title:Multiple Huawei Product memory leak vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=60969

Trust: 0.6

sources: CNVD: CNVD-2016-02289 // JVNDB: JVNDB-2015-007108 // CNNVD: CNNVD-201604-314

EXTERNAL IDS

db:NVDid:CVE-2015-8677

Trust: 3.5

db:JVNDBid:JVNDB-2015-007108

Trust: 0.8

db:CNNVDid:CNNVD-201604-314

Trust: 0.7

db:CNVDid:CNVD-2016-02289

Trust: 0.6

db:BIDid:90912

Trust: 0.4

db:VULHUBid:VHN-86638

Trust: 0.1

db:VULMONid:CVE-2015-8677

Trust: 0.1

sources: CNVD: CNVD-2016-02289 // VULHUB: VHN-86638 // VULMON: CVE-2015-8677 // BID: 90912 // JVNDB: JVNDB-2015-007108 // CNNVD: CNNVD-201604-314 // NVD: CVE-2015-8677

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160113-03-switch-en

Trust: 2.4

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-8677

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-8677

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://www.securityfocus.com/bid/90912

Trust: 0.1

sources: CNVD: CNVD-2016-02289 // VULHUB: VHN-86638 // VULMON: CVE-2015-8677 // JVNDB: JVNDB-2015-007108 // CNNVD: CNNVD-201604-314 // NVD: CVE-2015-8677

CREDITS

The vendor reported the issue.

Trust: 0.3

sources: BID: 90912

SOURCES

db:CNVDid:CNVD-2016-02289
db:VULHUBid:VHN-86638
db:VULMONid:CVE-2015-8677
db:BIDid:90912
db:JVNDBid:JVNDB-2015-007108
db:CNNVDid:CNNVD-201604-314
db:NVDid:CVE-2015-8677

LAST UPDATE DATE

2024-11-23T22:42:21.215000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-02289date:2016-04-19T00:00:00
db:VULHUBid:VHN-86638date:2019-06-20T00:00:00
db:VULMONid:CVE-2015-8677date:2019-06-20T00:00:00
db:BIDid:90912date:2016-07-06T14:51:00
db:JVNDBid:JVNDB-2015-007108date:2016-05-02T00:00:00
db:CNNVDid:CNNVD-201604-314date:2016-04-15T00:00:00
db:NVDid:CVE-2015-8677date:2024-11-21T02:38:57.140

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-02289date:2016-04-19T00:00:00
db:VULHUBid:VHN-86638date:2016-04-14T00:00:00
db:VULMONid:CVE-2015-8677date:2016-04-14T00:00:00
db:BIDid:90912date:2016-01-13T00:00:00
db:JVNDBid:JVNDB-2015-007108date:2016-05-02T00:00:00
db:CNNVDid:CNNVD-201604-314date:2016-04-15T00:00:00
db:NVDid:CVE-2015-8677date:2016-04-14T15:59:03.857