CVE-2014-8572

UnknownEPSS 0.94%

Last modified

CVE-2014-8572 is a vulnerability of currently unknown severity. Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earlier versions; S5300, S5700, S6300, S6700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions; S7700, S9300, S9300E, S9700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions could allow remote attackers to send a special SSH packet to the VRP device to cause a denial of service.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.

Description

Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earlier versions; S5300, S5700, S6300, S6700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions; S7700, S9300, S9300E, S9700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions could allow remote attackers to send a special SSH packet to the VRP device to cause a denial of service.

Metrics

EPSS Probability
0.94%

56.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiAc6605 Firmwareac6605_v200r001c00
HuaweiAc6605 Firmwareac6605_v200r002c00
HuaweiAcu Firmwareacu_v200r001c00
HuaweiAcu Firmwareacu_v200r002c00
HuaweiS Series Firmwarev100r006c05
HuaweiS5300 Firmware<= v200r005c00spc300
HuaweiS5300 Firmwarev100r006
HuaweiS5300 Firmwarev200r001
HuaweiS5300 Firmwarev200r002
HuaweiS5300 Firmwarev200r003
HuaweiS5700 Firmware<= v200r005c00spc300
HuaweiS5700 Firmwarev100r006
HuaweiS5700 Firmwarev200r001
HuaweiS5700 Firmwarev200r002
HuaweiS5700 Firmwarev200r003
HuaweiS6700 Firmware<= v200r005c00spc300
HuaweiS6700 Firmwarev100r006
HuaweiS6700 Firmwarev200r001
HuaweiS6700 Firmwarev200r002
HuaweiS6700 Firmwarev200r003
HuaweiS6300 Firmware<= v200r005c00spc300
HuaweiS6300 Firmwarev100r006
HuaweiS6300 Firmwarev200r001
HuaweiS6300 Firmwarev200r002
HuaweiS6300 Firmwarev200r003
HuaweiS7700 Firmware<= v200r005c00spc300
HuaweiS7700 Firmwarev100r006
HuaweiS7700 Firmwarev200r001
HuaweiS7700 Firmwarev200r002
HuaweiS7700 Firmwarev200r003
HuaweiS9700 Firmware<= v200r005c00spc300
HuaweiS9700 Firmwarev100r006
HuaweiS9700 Firmwarev200r001
HuaweiS9700 Firmwarev200r002
HuaweiS9700 Firmwarev200r003
HuaweiS9300 Firmware<= v200r005c00spc300
HuaweiS9300 Firmwarev100r006
HuaweiS9300 Firmwarev200r001
HuaweiS9300 Firmwarev200r002
HuaweiS9300 Firmwarev200r003
HuaweiS9300e Firmware<= v200r005c00spc300
HuaweiS9300e Firmwarev100r006
HuaweiS9300e Firmwarev200r001
HuaweiS9300e Firmwarev200r002
HuaweiS9300e Firmwarev200r003

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-8572?
Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earlier versions; S5300, S5700, S6300, S6700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions; S7700, S9300, S9300E, S9700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions could allow remote attackers to send a special SSH packet to the VRP device to cause a denial of service.
How severe is CVE-2014-8572?
Severity scoring for CVE-2014-8572 is pending analysis. The EPSS model estimates a 0.94% probability of exploitation in the next 30 days.
How do I fix CVE-2014-8572?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8572?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST