ID

VAR-201704-0464


CVE

CVE-2014-8570


TITLE

plural Huawei Device in the product software IP Vulnerability that could lead to address disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2014-008288

DESCRIPTION

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with software V200R002, V200R003, V200R005; S12708, S12712 with software V200R005; 5700HI, 5300HI with software V100R006, V200R001, V200R002, V200R003, V200R005; 5710EI, 5310EI with software V200R002, V200R003, V200R005; 5710HI, 5310HI with software V200R003, V200R005; 6700EI, 6300EI with software V200R005 could cause a leak of IP addresses of devices, related to unintended interface support for VRP MPLS LSP Ping. Huawei S9300 and other Huawei S series switches are Huawei. An information disclosure vulnerability exists in several Huawei switches that use the VRP platform. The Huawei S9300 and others are all S-series switches of China's Huawei (Huawei). The following products and versions are affected: Huawei S300 V100R002 version, V100R003 version, V100R006 version, V200R001 version, V200R002 version, V200R003 version; S9303 V100R002 version, V100R003 version, V200R001 version, V200R003 version; V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S9312 V100R002 Version, V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S7700 V100R002 Version, V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S7703 V100R002 Version, V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S7706 V100R002 Version, V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S7712 V100R002 Version, V100R003 Version, V100R006 Version, V200R001 Version, V200R002 Version, V200R003 Version; S9300E V200R001 Version, V200R002 Version, V200R003 Version, V200R005 Version; S9303E V200R001 Version, V200R002 Version, V200R003 Version, V200R005 Version; S9306E V200R001 Version, V200R002 Version, V200R003 Version, V200R005 Version; S9312E

Trust: 2.25

sources: NVD: CVE-2014-8570 // JVNDB: JVNDB-2014-008288 // CNVD: CNVD-2017-04631 // VULHUB: VHN-76515

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-04631

AFFECTED PRODUCTS

vendor:huaweimodel:5700hiscope:eqversion:v200r003

Trust: 1.6

vendor:huaweimodel:5700hiscope:eqversion:v200r005

Trust: 1.6

vendor:huaweimodel:5700hiscope:eqversion:v200r002

Trust: 1.6

vendor:huaweimodel:5300hiscope:eqversion:v200r005

Trust: 1.6

vendor:huaweimodel:5300hiscope:eqversion:v200r002

Trust: 1.6

vendor:huaweimodel:5300hiscope:eqversion:v200r003

Trust: 1.6

vendor:huaweimodel:5300hiscope:eqversion:v100r006

Trust: 1.6

vendor:huaweimodel:5300hiscope:eqversion:v200r001

Trust: 1.6

vendor:huaweimodel:5710eiscope:eqversion:v200r002

Trust: 1.6

vendor:huaweimodel:5710eiscope:eqversion:v200r003

Trust: 1.6

vendor:huaweimodel:s7700scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s9700scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:5310hiscope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:5310eiscope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:5310eiscope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:6700eiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9312escope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9703scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9703scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s12712scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9712scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9303escope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9706scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s12708scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:6300eiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s9303escope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9303escope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9312escope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:5710hiscope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9306escope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9706scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s9312escope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9312escope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:5700hiscope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9712scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9300escope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9706scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9706scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9306escope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:5710hiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v100r003

Trust: 1.0

vendor:huaweimodel:s9306escope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v100r002

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9306escope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9700scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300escope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:5710eiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9306scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9703scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s7703scope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9712scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300scope:eqversion:v100r006

Trust: 1.0

vendor:huaweimodel:s9700scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s9700scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9300escope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7700scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9300escope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9303scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:5310hiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s9312scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7712scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:5700hiscope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:5310eiscope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v200r003

Trust: 1.0

vendor:huaweimodel:s7706scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9303escope:eqversion:v200r001

Trust: 1.0

vendor:huaweimodel:s9712scope:eqversion:v200r002

Trust: 1.0

vendor:huaweimodel:s9703scope:eqversion:v200r005

Trust: 1.0

vendor:huaweimodel:s7700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s7703scope: - version: -

Trust: 0.8

vendor:huaweimodel:s7706scope: - version: -

Trust: 0.8

vendor:huaweimodel:s7712scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300escope: - version: -

Trust: 0.8

vendor:huaweimodel:s9303scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9303escope: - version: -

Trust: 0.8

vendor:huaweimodel:s9306scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9306escope: - version: -

Trust: 0.8

vendor:huaweimodel:s9312scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9312escope: - version: -

Trust: 0.8

vendor:huaweimodel:s9700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9703scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9706scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9712scope: - version: -

Trust: 0.8

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v100r002scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v100r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v100r006scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v200r001scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v200r002scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v200r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300/ s9303/ s9306/ s9312/ s7700/ s7703/ s7706/ s7712 v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300e/ s9303e/ s9306e/ s9312e/ s9700/ s9703/ s9706/ s9712 v200r001scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300e/ s9303e/ s9306e/ s9312e/ s9700/ s9703/ s9706/ s9712 v200r002scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300e/ s9303e/ s9306e/ s9312e/ s9700/ s9703/ s9706/ s9712 v200r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9300e/ s9303e/ s9306e/ s9312e/ s9700/ s9703/ s9706/ s9712 v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12708/ s12712 v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:5700hi/5300hi v100r006scope: - version: -

Trust: 0.6

vendor:huaweimodel:5700hi/5300hi v200r001scope: - version: -

Trust: 0.6

vendor:huaweimodel:5700hi/5300hi v200r002scope: - version: -

Trust: 0.6

vendor:huaweimodel:5700hi/5300hi v200r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:5700hi/5300hi v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:5710ei/5310ei v200r002scope: - version: -

Trust: 0.6

vendor:huaweimodel:5710ei/5310ei v200r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:5710ei/5310ei v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:5710hi/5310hi v200r003scope: - version: -

Trust: 0.6

vendor:huaweimodel:5710hi/5310hi v200r005scope: - version: -

Trust: 0.6

vendor:huaweimodel:6700ei/6300ei v200r005scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-04631 // JVNDB: JVNDB-2014-008288 // CNNVD: CNNVD-201704-210 // NVD: CVE-2014-8570

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8570
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8570
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2017-04631
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201704-210
value: MEDIUM

Trust: 0.6

VULHUB: VHN-76515
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-8570
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-04631
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-76515
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2014-8570
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-04631 // VULHUB: VHN-76515 // JVNDB: JVNDB-2014-008288 // CNNVD: CNNVD-201704-210 // NVD: CVE-2014-8570

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-76515 // JVNDB: JVNDB-2014-008288 // NVD: CVE-2014-8570

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-210

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201704-210

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008288

PATCH

title:Huawei-SA-20140924-01-VRPurl:http://www.huawei.com/en/psirt/security-advisories/hw-372145

Trust: 0.8

title:Patches for various Huawei switch information disclosure vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/91943

Trust: 0.6

title:Various Huawei switch information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=69056

Trust: 0.6

sources: CNVD: CNVD-2017-04631 // JVNDB: JVNDB-2014-008288 // CNNVD: CNNVD-201704-210

EXTERNAL IDS

db:NVDid:CVE-2014-8570

Trust: 3.1

db:JVNDBid:JVNDB-2014-008288

Trust: 0.8

db:CNNVDid:CNNVD-201704-210

Trust: 0.7

db:CNVDid:CNVD-2017-04631

Trust: 0.6

db:VULHUBid:VHN-76515

Trust: 0.1

sources: CNVD: CNVD-2017-04631 // VULHUB: VHN-76515 // JVNDB: JVNDB-2014-008288 // CNNVD: CNNVD-201704-210 // NVD: CVE-2014-8570

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/hw-372145

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8570

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2014-8570

Trust: 0.8

sources: CNVD: CNVD-2017-04631 // VULHUB: VHN-76515 // JVNDB: JVNDB-2014-008288 // CNNVD: CNNVD-201704-210 // NVD: CVE-2014-8570

SOURCES

db:CNVDid:CNVD-2017-04631
db:VULHUBid:VHN-76515
db:JVNDBid:JVNDB-2014-008288
db:CNNVDid:CNNVD-201704-210
db:NVDid:CVE-2014-8570

LAST UPDATE DATE

2024-11-23T22:42:12.361000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-04631date:2017-04-19T00:00:00
db:VULHUBid:VHN-76515date:2017-04-10T00:00:00
db:JVNDBid:JVNDB-2014-008288date:2017-05-08T00:00:00
db:CNNVDid:CNNVD-201704-210date:2017-04-06T00:00:00
db:NVDid:CVE-2014-8570date:2024-11-21T02:19:21.450

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-04631date:2017-04-19T00:00:00
db:VULHUBid:VHN-76515date:2017-04-02T00:00:00
db:JVNDBid:JVNDB-2014-008288date:2017-05-08T00:00:00
db:CNNVDid:CNNVD-201704-210date:2017-04-06T00:00:00
db:NVDid:CVE-2014-8570date:2017-04-02T20:59:00.343