Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-8087


Huawei NE20E-S, NE40E-M, and NE40E-M2 routers with software before V800R007C10SPC100 and NE40E and NE80E routers with software before V800R007C00SPC100 allows remote attackers to send packets to other VPNs and conduct flooding attacks via a crafted MPLS forwarding packet, aka a "VPN routing and forwarding (VRF) hopping vulnerability."


Published

2015-11-19T20:59:11.960

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application huawei ne_router_software ≤ v800r006 Yes
Application huawei ne_router_software ≤ v800r007c00 Yes
Hardware huawei ne20e-s - No
Hardware huawei ne40e-m - No
Hardware huawei ne40e-m2 - No
Application huawei ne_router_software ≤ v800r006 Yes
Hardware huawei ne40e - No
Hardware huawei ne80e - No

References