Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8784


Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some parameters in the packet are abnormal, the LDP processing module does not release the memory to handle the packet, resulting in memory leak.


Published

2018-03-09T21:29:00.300

Last Modified

2024-11-21T03:00:04.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 4.3 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei cloudengine_12800_firmware v100r003c00 Yes
Operating System huawei cloudengine_12800_firmware v100r003c10 Yes
Operating System huawei cloudengine_12800_firmware v100r005c00 Yes
Operating System huawei cloudengine_12800_firmware v100r005c10 Yes
Operating System huawei cloudengine_12800_firmware v100r006c00 Yes
Hardware huawei cloudengine_12800 - No

References