CVE-2017-17318

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
30/04/2018
Last modified:
06/06/2018

Description

Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http request to device, the webserver process will try to apply too much memory which can cause the device to become unable to respond. An attacker can launch a DoS attack by exploiting this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:e5771h-937_firmware:*:*:*:*:*:*:*:* v200r001b329d05sp00c1308 (excluding)
cpe:2.3:h:huawei:e5771h-937:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:e5771h-937_firmware:*:*:*:*:*:*:*:* v200r001b328d62sp00c1133 (excluding)
cpe:2.3:h:huawei:e5771h-937:-:*:*:*:*:*:*:*