ID

VAR-201712-0808


CVE

CVE-2017-15324


TITLE

Huawei S5700 and S6700 Input validation vulnerability in other software

Trust: 0.8

sources: JVNDB: JVNDB-2017-011576

DESCRIPTION

Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending malformed NQA packets to the target device. Successful exploitation could make the device restart. HuaweiS12700 is an intelligent routing switch of China Huawei. The following products and versions are affected: Huawei S12700 V200R006C00 Version, V200R007C00 Version, V200R007C01 Version, V200R007C20 Version, V200R008C00 Version, V200R009C00 Version, V200R010C00 Version; S1700 V200R006C10 Version, V200R009C00 Version, V200R010C00 Version; S2700 V200R006C00 Version, V200R006C10 Version, V200R007C00 Version, V200R008C00 Version, V200R009C00 Version, V200R010C00 Version, V200R011C00 Version; S5700 V200R005C00 Version, V200R006C00 Version, V200R007C00 Version, V200R008C00 Version, V200R009C00 Version, V200R010C00 Version, V200R011C00 Version; S6700 V200R005C00 Version, V200R008C00 Version, V200R009C00 Version, V200R010C00 Version; S7700 V200R006C00 Version , version V200R007C00, version V200R008C00, version V200R009C00, version V200R010C00;

Trust: 2.25

sources: NVD: CVE-2017-15324 // JVNDB: JVNDB-2017-011576 // CNVD: CNVD-2017-37724 // VULHUB: VHN-106135

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-37724

AFFECTED PRODUCTS

vendor:huaweimodel:s5700scope:eqversion:v200r005c00

Trust: 2.4

vendor:huaweimodel:s6700scope:eqversion:v200r005c00

Trust: 2.4

vendor:huaweimodel:s9700 v200r008c00scope: - version: -

Trust: 1.2

vendor:huaweimodel:s5700 v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r007c01scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r006c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r008c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r007c20scope: - version: -

Trust: 0.6

vendor:huaweimodel:s12700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s1700 v200r006c10scope: - version: -

Trust: 0.6

vendor:huaweimodel:s1700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s1700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r006c10scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r009c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s2700 v200r011c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s5700 v200r011c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s7700 v200r010c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r007c01scope: - version: -

Trust: 0.6

vendor:huaweimodel:s9700 v200r010c00scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-37724 // JVNDB: JVNDB-2017-011576 // CNNVD: CNNVD-201712-688 // NVD: CVE-2017-15324

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15324
value: HIGH

Trust: 1.0

NVD: CVE-2017-15324
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-37724
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201712-688
value: HIGH

Trust: 0.6

VULHUB: VHN-106135
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-15324
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-37724
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-106135
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15324
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-37724 // VULHUB: VHN-106135 // JVNDB: JVNDB-2017-011576 // CNNVD: CNNVD-201712-688 // NVD: CVE-2017-15324

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-106135 // JVNDB: JVNDB-2017-011576 // NVD: CVE-2017-15324

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201712-688

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201712-688

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-011576

PATCH

title:huawei-sa-20171206-01-nqaurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-nqa-en

Trust: 0.8

title:Patches for several Huawei Product Denial of Service Vulnerabilities (CNVD-2017-37724)url:https://www.cnvd.org.cn/patchInfo/show/111253

Trust: 0.6

title:Multiple Huawei Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=77226

Trust: 0.6

sources: CNVD: CNVD-2017-37724 // JVNDB: JVNDB-2017-011576 // CNNVD: CNNVD-201712-688

EXTERNAL IDS

db:NVDid:CVE-2017-15324

Trust: 3.1

db:JVNDBid:JVNDB-2017-011576

Trust: 0.8

db:CNNVDid:CNNVD-201712-688

Trust: 0.7

db:CNVDid:CNVD-2017-37724

Trust: 0.6

db:VULHUBid:VHN-106135

Trust: 0.1

sources: CNVD: CNVD-2017-37724 // VULHUB: VHN-106135 // JVNDB: JVNDB-2017-011576 // CNNVD: CNNVD-201712-688 // NVD: CVE-2017-15324

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-nqa-en

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15324

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-15324

Trust: 0.8

url:http://www.huawei.com/cn/psirt/security-advisories/2017/huawei-sa-20171206-01-nqa-cn

Trust: 0.6

sources: CNVD: CNVD-2017-37724 // VULHUB: VHN-106135 // JVNDB: JVNDB-2017-011576 // CNNVD: CNNVD-201712-688 // NVD: CVE-2017-15324

CREDITS

Huawei internal tester

Trust: 0.6

sources: CNNVD: CNNVD-201712-688

SOURCES

db:CNVDid:CNVD-2017-37724
db:VULHUBid:VHN-106135
db:JVNDBid:JVNDB-2017-011576
db:CNNVDid:CNNVD-201712-688
db:NVDid:CVE-2017-15324

LAST UPDATE DATE

2024-11-23T22:56:02.265000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-37724date:2017-12-21T00:00:00
db:VULHUBid:VHN-106135date:2018-01-17T00:00:00
db:JVNDBid:JVNDB-2017-011576date:2018-01-22T00:00:00
db:CNNVDid:CNNVD-201712-688date:2017-12-20T00:00:00
db:NVDid:CVE-2017-15324date:2024-11-21T03:14:27.940

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-37724date:2017-12-21T00:00:00
db:VULHUBid:VHN-106135date:2017-12-22T00:00:00
db:JVNDBid:JVNDB-2017-011576date:2018-01-22T00:00:00
db:CNNVDid:CNNVD-201712-688date:2017-12-20T00:00:00
db:NVDid:CVE-2017-15324date:2017-12-22T17:29:13.470