CVE-2016-8795
Last modified
CVE-2016-8795 is a vulnerability of currently unknown severity. Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 7800 with software V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 8800 with software V100R006C00; and Secospace USG6600 with software V500R001C00 allow remote unauthenticated attackers to craft specific IPFPM packets to trigger an integer overflow and cause the device to reset.. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 7800 with software V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 8800 with software V100R006C00; and Secospace USG6600 with software V500R001C00 allow remote unauthenticated attackers to craft specific IPFPM packets to trigger an integer overflow and cause the device to reset.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Cloudengine 5800 Firmware | v100r002c00 |
| Huawei | Cloudengine 5800 Firmware | v100r003c00 |
| Huawei | Cloudengine 5800 Firmware | v100r003c10 |
| Huawei | Cloudengine 5800 Firmware | v100r005c00 |
| Huawei | Cloudengine 5800 Firmware | v100r005c10 |
| Huawei | Cloudengine 5800 Firmware | v100r006c00 |
| Huawei | Cloudengine 6800 Firmware | v100r002c00 |
| Huawei | Cloudengine 6800 Firmware | v100r003c00 |
| Huawei | Cloudengine 6800 Firmware | v100r003c10 |
| Huawei | Cloudengine 6800 Firmware | v100r005c00 |
| Huawei | Cloudengine 6800 Firmware | v100r005c10 |
| Huawei | Cloudengine 6800 Firmware | v100r006c00 |
| Huawei | Cloudengine 12800 Firmware | v100r002c00 |
| Huawei | Cloudengine 12800 Firmware | v100r003c00 |
| Huawei | Cloudengine 12800 Firmware | v100r003c10 |
| Huawei | Cloudengine 12800 Firmware | v100r005c00 |
| Huawei | Cloudengine 12800 Firmware | v100r005c10 |
| Huawei | Cloudengine 12800 Firmware | v100r006c00 |
| Huawei | Cloudengine 7800 Firmware | v100r003c00 |
| Huawei | Cloudengine 7800 Firmware | v100r003c10 |
| Huawei | Cloudengine 7800 Firmware | v100r005c00 |
| Huawei | Cloudengine 7800 Firmware | v100r005c10 |
| Huawei | Cloudengine 7800 Firmware | v100r006c00 |
| Huawei | Cloudengine 8800 Firmware | v100r006c00 |
| Huawei | Secospace Usg6600 Firmware | v500r001c00 |
References
- http://www.securityfocus.com/bid/94504Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/94504Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8795?
How severe is CVE-2016-8795?
How do I fix CVE-2016-8795?
Are you affected by CVE-2016-8795?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
