XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C02, V200R008C00, V200R009C00, V200R010C00,S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,eCNS210_TD V100R004C10, V100R004C10SPC003, V100R004C10SPC100, V100R004C10SPC101, V100R004C10SPC102, V100R004C10SPC200, V100R004C10SPC221, V100R004C10SPC400 has a DOS vulnerability. An attacker may craft specific XML files to the affected products. Due to not check the specially XML file and to parse this file, successful exploit will result in DOS attacks.
This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 4.7, requiring local system access to exploit but requires specific conditions to be met though user interaction is required and does not require pre-existing privileges . The vulnerability impacts and availability (service disruption) for affected systems. Impacting 14 products from huawei, from huawei, from huawei and 11 others, organizations running these solutions should prioritize assessment and patching.
First disclosed in 2018, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.
2018-02-15T16:29:01.047
2024-11-21T03:14:30.757
Modified
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | s12700_firmware | v200r005c00 | Yes |
| Hardware | huawei | s12700 | - | No |
| Operating System | huawei | s1700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s1700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s1700 | - | No |
| Operating System | huawei | s5700_firmware | v200r001c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r002c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r003c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r003c02 | Yes |
| Operating System | huawei | s5700_firmware | v200r005c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r006c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r007c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r008c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s5700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s5700 | - | No |
| Operating System | huawei | s6700_firmware | v200r001c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r002c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r003c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r005c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r005c02 | Yes |
| Operating System | huawei | s6700_firmware | v200r008c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s6700 | - | No |
| Operating System | huawei | s6700_firmware | v200r001c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r002c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r003c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r005c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r005c02 | Yes |
| Operating System | huawei | s6700_firmware | v200r008c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s6700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s6700 | - | No |
| Operating System | huawei | s7700_firmware | v200r001c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r002c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r003c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r005c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r006c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r007c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r008c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s7700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s7700 | - | No |
| Operating System | huawei | s9700_firmware | v200r001c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r002c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r003c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r005c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r006c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r007c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r008c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r009c00 | Yes |
| Operating System | huawei | s9700_firmware | v200r010c00 | Yes |
| Hardware | huawei | s9700 | - | No |
| Operating System | huawei | ecns210_td_firmware | v100r004c10 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc003 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc100 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc101 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc102 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc200 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc221 | Yes |
| Operating System | huawei | ecns210_td_firmware | v100r004c10spc400 | Yes |
| Hardware | huawei | ecns210_td | - | No |
SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For huawei's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.