Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8782


Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices repeatedly. Due to improper validation of some specific fields of the packet, the LDP processing module does not release the memory, resulting in memory leak.


Published

2018-03-09T21:29:00.207

Last Modified

2024-11-21T03:00:04.160

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei cloudengine_12800_firmware v100r003c00 Yes
Operating System huawei cloudengine_12800_firmware v100r003c10 Yes
Operating System huawei cloudengine_12800_firmware v100r005c00 Yes
Operating System huawei cloudengine_12800_firmware v100r005c10 Yes
Operating System huawei cloudengine_12800_firmware v100r006c00 Yes
Hardware huawei cloudengine_12800 - No

References