Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.
2018-02-15T16:29:00.953
2024-11-21T03:14:30.543
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei | ar120-s_firmware | v200r006c10 | Yes |
Operating System | huawei | ar120-s_firmware | v200r007c00 | Yes |
Operating System | huawei | ar120-s_firmware | v200r008c20 | Yes |
Operating System | huawei | ar120-s_firmware | v200r008c30 | Yes |
Operating System | huawei | ar1200_firmware | v200r007c01 | Yes |
Operating System | huawei | ar1200_firmware | v200r007c02 | Yes |
Operating System | huawei | ar3200_firmware | v200r006c11 | Yes |
Operating System | huawei | ar3200_firmware | v200r008c00 | Yes |
Operating System | huawei | ar3200_firmware | v200r008c10 | Yes |
Hardware | huawei | ar3200 | - | No |