CVE-2016-8785
Last modified
CVE-2016-8785 is a vulnerability of currently unknown severity. Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory data and possibly leading to sensitive information leakage.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory data and possibly leading to sensitive information leakage.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | S12700 Firmware | v200r007c00 |
| Huawei | S12700 Firmware | v200r008c00 |
| Huawei | S5700 Firmware | v200r007c00 |
| Huawei | S7700 Firmware | v200r002c00 |
| Huawei | S7700 Firmware | v200r005c00 |
| Huawei | S7700 Firmware | v200r006c00 |
| Huawei | S7700 Firmware | v200r007c00 |
| Huawei | S7700 Firmware | v200r008c00 |
| Huawei | S9700 Firmware | v200r007c00 |
References
- http://www.securityfocus.com/bid/95149Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/95149Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8785?
How severe is CVE-2016-8785?
How do I fix CVE-2016-8785?
Are you affected by CVE-2016-8785?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
