CVE-2016-6178

UnknownEPSS 2.99%

Last modified

CVE-2016-6178 is a vulnerability of currently unknown severity. Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.. EPSS estimates a 2.99% chance of exploitation in the next 30 days.

Description

Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.

Metrics

EPSS Probability
2.99%

85.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiNe5000e Firmwarev800r006c00
HuaweiCloudengine 12800 Firmwarev100r003c00
HuaweiCloudengine 12800 Firmwarev100r003c10
HuaweiCloudengine 12800 Firmwarev100r005c00
HuaweiCloudengine 12800 Firmwarev100r005c10
HuaweiPtn 6900-2-M8 Firmwarev800r007c00
HuaweiCx600 Firmwarev600r008c20
HuaweiCx600 Firmwarev800r006c00
HuaweiCx600 Firmwarev800r006c20
HuaweiCx600 Firmwarev800r007c00
HuaweiNe40e Firmwarev600r008c20
HuaweiNe40e Firmwarev800r006c00
HuaweiNe40e Firmwarev800r006c20
HuaweiNe40e Firmwarev800r006c30
HuaweiNe40e Firmwarev800r007c00

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-6178?
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.
How severe is CVE-2016-6178?
Severity scoring for CVE-2016-6178 is pending analysis. The EPSS model estimates a 2.99% probability of exploitation in the next 30 days.
How do I fix CVE-2016-6178?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-6178?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST