ID

VAR-201610-0209


CVE

CVE-2016-8278


TITLE

plural Huawei USG Service disruption in product software (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2016-005102

DESCRIPTION

Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attackers to cause a denial of service (device restart) via an unspecified URL. Multiple Huawei products are prone to a remote denial-of-service vulnerability. The Huawei USG9520 and others are the unified security gateway products of China's Huawei (Huawei). The following versions are affected: Huawei USG9520 V300R001C01; USG9560 V300R001C01; USG9580 V300R001C01

Trust: 1.98

sources: NVD: CVE-2016-8278 // JVNDB: JVNDB-2016-005102 // BID: 93099 // VULHUB: VHN-97098

AFFECTED PRODUCTS

vendor:huaweimodel:usg9560scope:eqversion:v300r001c01

Trust: 1.6

vendor:huaweimodel:usg9520scope:eqversion:v300r001c01

Trust: 1.6

vendor:huaweimodel:usg9580scope:eqversion:v300r001c01

Trust: 1.6

vendor:huaweimodel:usg9520scope: - version: -

Trust: 0.8

vendor:huaweimodel:usg9520scope:ltversion:v300r001c01spca00

Trust: 0.8

vendor:huaweimodel:usg9560scope: - version: -

Trust: 0.8

vendor:huaweimodel:usg9560scope:ltversion:v300r001c01spca00

Trust: 0.8

vendor:huaweimodel:usg9580scope: - version: -

Trust: 0.8

vendor:huaweimodel:usg9580scope:ltversion:v300r001c01spca00

Trust: 0.8

vendor:huaweimodel:usg9580 v300r001c01scope: - version: -

Trust: 0.3

vendor:huaweimodel:usg9560 v300r001c01scope: - version: -

Trust: 0.3

vendor:huaweimodel:usg9520 v300r001c01scope: - version: -

Trust: 0.3

vendor:huaweimodel:usg9580 v300r001c01spc800scope:neversion: -

Trust: 0.3

vendor:huaweimodel:usg9560 v300r001c01spc800scope:neversion: -

Trust: 0.3

vendor:huaweimodel:usg9520 v300r001c01spc800scope:neversion: -

Trust: 0.3

sources: BID: 93099 // JVNDB: JVNDB-2016-005102 // CNNVD: CNNVD-201609-499 // NVD: CVE-2016-8278

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-8278
value: HIGH

Trust: 1.0

NVD: CVE-2016-8278
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201609-499
value: HIGH

Trust: 0.6

VULHUB: VHN-97098
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-8278
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-97098
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-8278
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-97098 // JVNDB: JVNDB-2016-005102 // CNNVD: CNNVD-201609-499 // NVD: CVE-2016-8278

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-97098 // JVNDB: JVNDB-2016-005102 // NVD: CVE-2016-8278

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201609-499

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201609-499

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-005102

PATCH

title:huawei-sa-20160921-02-firewallurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160921-02-firewall-en

Trust: 0.8

title:Multiple Huawei Product denial of service vulnerability fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=64236

Trust: 0.6

sources: JVNDB: JVNDB-2016-005102 // CNNVD: CNNVD-201609-499

EXTERNAL IDS

db:NVDid:CVE-2016-8278

Trust: 2.8

db:BIDid:93099

Trust: 2.0

db:JVNDBid:JVNDB-2016-005102

Trust: 0.8

db:CNNVDid:CNNVD-201609-499

Trust: 0.7

db:VULHUBid:VHN-97098

Trust: 0.1

sources: VULHUB: VHN-97098 // BID: 93099 // JVNDB: JVNDB-2016-005102 // CNNVD: CNNVD-201609-499 // NVD: CVE-2016-8278

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160921-02-firewall-en

Trust: 2.0

url:http://www.securityfocus.com/bid/93099

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-8278

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-8278

Trust: 0.8

url:http://www.huawei.com

Trust: 0.3

sources: VULHUB: VHN-97098 // BID: 93099 // JVNDB: JVNDB-2016-005102 // CNNVD: CNNVD-201609-499 // NVD: CVE-2016-8278

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 93099

SOURCES

db:VULHUBid:VHN-97098
db:BIDid:93099
db:JVNDBid:JVNDB-2016-005102
db:CNNVDid:CNNVD-201609-499
db:NVDid:CVE-2016-8278

LAST UPDATE DATE

2024-11-23T22:22:43.602000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-97098date:2016-10-06T00:00:00
db:BIDid:93099date:2016-09-23T00:00:00
db:JVNDBid:JVNDB-2016-005102date:2016-10-06T00:00:00
db:CNNVDid:CNNVD-201609-499date:2016-10-08T00:00:00
db:NVDid:CVE-2016-8278date:2024-11-21T02:59:03.993

SOURCES RELEASE DATE

db:VULHUBid:VHN-97098date:2016-10-03T00:00:00
db:BIDid:93099date:2016-09-21T00:00:00
db:JVNDBid:JVNDB-2016-005102date:2016-10-06T00:00:00
db:CNNVDid:CNNVD-201609-499date:2016-09-22T00:00:00
db:NVDid:CVE-2016-8278date:2016-10-03T21:59:11.693