CVE-2017-2690

UnknownEPSS 0.23%

Last modified

CVE-2017-2690 is a vulnerability of currently unknown severity. SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20, V200R003C30,eSpace U1930 with software V200R003C20 and V200R003C30,eSpace U1960 with software V200R003C20, V200R003C30,eSpace U1980 with software V200R003C20, V200R003C30,eSpace U1981 with software V200R003C20 and V200R003C30 have an denial of service (DoS) vulnerability, which allow an attacker with specific permission to craft a file containing malicious data and upload it to the device to exhaust memory, causing a DoS condition.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.

Description

SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20, V200R003C30,eSpace U1930 with software V200R003C20 and V200R003C30,eSpace U1960 with software V200R003C20, V200R003C30,eSpace U1980 with software V200R003C20, V200R003C30,eSpace U1981 with software V200R003C20 and V200R003C30 have an denial of service (DoS) vulnerability, which allow an attacker with specific permission to craft a file containing malicious data and upload it to the device to exhaust memory, causing a DoS condition.

Metrics

EPSS Probability
0.23%

13.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiSoftco Firmwarev200r003c20
HuaweiEspace U1910 Firmwarev200r003c00
HuaweiEspace U1910 Firmwarev200r003c20
HuaweiEspace U1910 Firmwarev200r003c30
HuaweiEspace U1911 Firmwarev200r003c20
HuaweiEspace U1911 Firmwarev200r003c30
HuaweiEspace U1930 Firmwarev200r003c20
HuaweiEspace U1930 Firmwarev200r003c30
HuaweiEspace U1960 Firmwarev200r003c20
HuaweiEspace U1960 Firmwarev200r003c30
HuaweiEspace U1980 Firmwarev200r003c20
HuaweiEspace U1980 Firmwarev200r003c30
HuaweiEspace U1981 Firmwarev200r003c20
HuaweiEspace U1981 Firmwarev200r003c30

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-2690?
SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20, V200R003C30,eSpace U1930 with software V200R003C20 and V200R003C30,eSpace U1960 with software V200R003C20, V200R003C30,eSpace U1980 with software V200R003C20, V200R003C30,eSpace U1981 with software V200R003C20 and V200R003C30 have an denial of service (DoS) vulnerability, which allow an attacker with specific permission to craft a file containing malicious data and upload it to the device to exhaust memory, causing a DoS condition.
How severe is CVE-2017-2690?
Severity scoring for CVE-2017-2690 is pending analysis. The EPSS model estimates a 0.23% probability of exploitation in the next 30 days.
How do I fix CVE-2017-2690?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-2690?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST