Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-8083


An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not properly initialize memory when processing timeout messages, which allows remote attackers to cause a denial of service (out-of-bounds memory access and device restart) via unknown vectors.


Published

2015-11-19T20:59:10.913

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei espace_firmware ≤ v100r001c20 Yes
Hardware huawei espace_unified_gateway_u1910 - No
Hardware huawei espace_unified_gateway_u1911 - No
Hardware huawei espace_unified_gateway_u1930 - No
Hardware huawei espace_unified_gateway_u1960 - No
Hardware huawei espace_unified_gateway_u1980 - No
Hardware huawei espace_unified_gateway_u1981 - No

References