Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability. When a user executes a query command after the device received an abnormal OSPF message, the software writes data past the end of the intended buffer due to the insufficient verification of the input data. An unauthenticated, remote attacker could exploit this vulnerability by sending abnormal OSPF messages to the device. A successful exploit could cause the system to crash.

Project Subscriptions

Vendors Products
Ar120-s Subscribe
Ar120-s Firmware Subscribe
Ar1200-s Subscribe
Ar1200-s Firmware Subscribe
Ar1200 Firmware Subscribe
Ar150-s Subscribe
Ar150-s Firmware Subscribe
Ar150 Firmware Subscribe
Ar160 Firmware Subscribe
Ar200-s Subscribe
Ar200-s Firmware Subscribe
Ar200 Firmware Subscribe
Ar2200-s Subscribe
Ar2200-s Firmware Subscribe
Ar3200 Firmware Subscribe
Ar510 Firmware Subscribe
Netengine16ex Subscribe
Netengine16ex Firmware Subscribe
S12700 Firmware Subscribe
S2700 Firmware Subscribe
S5700 Firmware Subscribe
S6700 Firmware Subscribe
S7700 Firmware Subscribe
S9700 Firmware Subscribe
Srg1300 Subscribe
Srg1300 Firmware Subscribe
Srg2300 Subscribe
Srg2300 Firmware Subscribe
Srg3300 Subscribe
Srg3300 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-8416 Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability. When a user executes a query command after the device received an abnormal OSPF message, the software writes data past the end of the intended buffer due to the insufficient verification of the input data. An unauthenticated, remote attacker could exploit this vulnerability by sending abnormal OSPF messages to the device. A successful exploit could cause the system to crash.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-05T20:43:59.885Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2017-17250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-09T17:29:01.547

Modified: 2024-11-21T03:17:42.510

Link: CVE-2017-17250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses