ID

VAR-201803-1311


CVE

CVE-2017-15315


TITLE

plural Huawei Resource management vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2017-012815

DESCRIPTION

Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200 has a memory leak vulnerability. An authenticated attacker could execute special commands many times, the memory leaking happened, which would cause the device to reset finally. plural Huawei The product contains a resource management vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Huawei NIP6300 and others are all products of China Huawei (Huawei). Huawei NIP6300 is an intrusion prevention device. Secospace USG6300 is a firewall device. The following products and versions are affected: Huawei NIP6300 V500R001C20SPC100 Version, V500R001C20SPC200 Version; NIP6600 V500R001C20SPC100 Version, V500R001C20SPC200 Version; Secospace USG6300 V500R001C20SPC100 Version, V500R001C20SPC200 Version; Secospace USG6500 V500R001C20SPC100 Version, V500R001C20SPC200 Version

Trust: 1.71

sources: NVD: CVE-2017-15315 // JVNDB: JVNDB-2017-012815 // VULHUB: VHN-106125

AFFECTED PRODUCTS

vendor:huaweimodel:secospace usg6500scope:eqversion:v500r001c20spc100

Trust: 1.6

vendor:huaweimodel:secospace usg6300scope:eqversion:v500r001c20spc200

Trust: 1.6

vendor:huaweimodel:nip6300scope:eqversion:v500r001c20spc200

Trust: 1.6

vendor:huaweimodel:nip6600scope:eqversion:v500r001c20spc100

Trust: 1.6

vendor:huaweimodel:secospace usg6500scope:eqversion:v500r001c20spc200

Trust: 1.6

vendor:huaweimodel:secospace usg6300scope:eqversion:v500r001c20spc100

Trust: 1.6

vendor:huaweimodel:nip6300scope:eqversion:v500r001c20spc100

Trust: 1.6

vendor:huaweimodel:nip6600scope:eqversion:v500r001c20spc200

Trust: 1.6

vendor:huaweimodel:nip6300scope: - version: -

Trust: 0.8

vendor:huaweimodel:nip6600scope: - version: -

Trust: 0.8

vendor:huaweimodel:secospace usg6300scope: - version: -

Trust: 0.8

vendor:huaweimodel:secospace usg6500scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2017-012815 // CNNVD: CNNVD-201710-461 // NVD: CVE-2017-15315

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15315
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-15315
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201710-461
value: MEDIUM

Trust: 0.6

VULHUB: VHN-106125
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-15315
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-106125
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15315
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-106125 // JVNDB: JVNDB-2017-012815 // CNNVD: CNNVD-201710-461 // NVD: CVE-2017-15315

PROBLEMTYPE DATA

problemtype:CWE-772

Trust: 1.1

problemtype:CWE-399

Trust: 0.9

sources: VULHUB: VHN-106125 // JVNDB: JVNDB-2017-012815 // NVD: CVE-2017-15315

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201710-461

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201710-461

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-012815

PATCH

title:huawei-sa-20171129-01-commandurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-command-en

Trust: 0.8

title:Multiple Huawei product Patch Repair measures for module security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=100105

Trust: 0.6

sources: JVNDB: JVNDB-2017-012815 // CNNVD: CNNVD-201710-461

EXTERNAL IDS

db:NVDid:CVE-2017-15315

Trust: 2.5

db:JVNDBid:JVNDB-2017-012815

Trust: 0.8

db:CNNVDid:CNNVD-201710-461

Trust: 0.7

db:VULHUBid:VHN-106125

Trust: 0.1

sources: VULHUB: VHN-106125 // JVNDB: JVNDB-2017-012815 // CNNVD: CNNVD-201710-461 // NVD: CVE-2017-15315

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-command-en

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-15315

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-15315

Trust: 0.8

sources: VULHUB: VHN-106125 // JVNDB: JVNDB-2017-012815 // CNNVD: CNNVD-201710-461 // NVD: CVE-2017-15315

SOURCES

db:VULHUBid:VHN-106125
db:JVNDBid:JVNDB-2017-012815
db:CNNVDid:CNNVD-201710-461
db:NVDid:CVE-2017-15315

LAST UPDATE DATE

2024-11-23T22:59:05.407000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-106125date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-012815date:2018-04-19T00:00:00
db:CNNVDid:CNNVD-201710-461date:2019-10-23T00:00:00
db:NVDid:CVE-2017-15315date:2024-11-21T03:14:26.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-106125date:2018-03-09T00:00:00
db:JVNDBid:JVNDB-2017-012815date:2018-04-19T00:00:00
db:CNNVDid:CNNVD-201710-461date:2017-10-17T00:00:00
db:NVDid:CVE-2017-15315date:2018-03-09T21:29:00.517