CVE-2017-8147
Last modified
CVE-2017-8147 is a vulnerability of currently unknown severity. AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 6800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 7800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 8800 with software V100R006C00, V200R001C00,E600 V200R008C00,S12700 with software V200R005C00, V200R006C00, V200R007C00, V200R008C00,S1700 with software V100R006C00, V100R007C00, V200R006C00,S2300 with software V100R005C00, V100R006C00, V100R006C03, V100R006C05, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00,S2700 with software V100R005C00, V100R006C00, V100R006C03, V100R006C05, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00,S5300 with software V100R005C00, V100R006C00, V100R006C01, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S5700 with software V100R005C00, V100R006C00, V100R006C01, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S6300 with software V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R008C00,S6700 with software V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S7700 with software V100R003C00, V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S9300 with software V100R001C00, V100R002C00, V100R003C00, V100R006C00, V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R008C10,S9700 with software V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00,Secospace USG6600 V500R001C00SPC050 have a MaxAge LSA vulnerability due to improper OSPF implementation. When the device receives special LSA packets, the LS (Link Status) age would be set to MaxAge, 3600 seconds. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 6800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 7800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 8800 with software V100R006C00, V200R001C00,E600 V200R008C00,S12700 with software V200R005C00, V200R006C00, V200R007C00, V200R008C00,S1700 with software V100R006C00, V100R007C00, V200R006C00,S2300 with software V100R005C00, V100R006C00, V100R006C03, V100R006C05, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00,S2700 with software V100R005C00, V100R006C00, V100R006C03, V100R006C05, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R005C01, V200R005C02, V200R005C03, V200R006C00, V200R007C00, V200R008C00,S5300 with software V100R005C00, V100R006C00, V100R006C01, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S5700 with software V100R005C00, V100R006C00, V100R006C01, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S6300 with software V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R008C00,S6700 with software V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R003C02, V200R003C10, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S7700 with software V100R003C00, V100R006C00, V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00,S9300 with software V100R001C00, V100R002C00, V100R003C00, V100R006C00, V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R008C10,S9700 with software V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00,Secospace USG6600 V500R001C00SPC050 have a MaxAge LSA vulnerability due to improper OSPF implementation. When the device receives special LSA packets, the LS (Link Status) age would be set to MaxAge, 3600 seconds. An attacker can exploit this vulnerability to poison the route table and launch a DoS attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ac6005 Firmware | v200r006c10spc200 |
| Huawei | Ac6605 Firmware | v200r006c10spc200 |
| Huawei | Ar1200 Firmware | v200r005c10cp0582t |
| Huawei | Ar1200 Firmware | v200r005c10hp0581t |
| Huawei | Ar1200 Firmware | v200r005c20spc026t |
| Huawei | Ar200 Firmware | v200r005c20spc026t |
| Huawei | Ar3200 Firmware | v200r005c20spc026t |
| Huawei | Cloudengine 12800 Firmware | v100r003c00 |
| Huawei | Cloudengine 12800 Firmware | v100r005c00 |
| Huawei | Cloudengine 12800 Firmware | v100r005c10 |
| Huawei | Cloudengine 12800 Firmware | v100r006c00 |
| Huawei | Cloudengine 12800 Firmware | v200r001c00 |
| Huawei | Cloudengine 5800 Firmware | v100r003c00 |
| Huawei | Cloudengine 5800 Firmware | v100r005c00 |
| Huawei | Cloudengine 5800 Firmware | v100r005c10 |
| Huawei | Cloudengine 5800 Firmware | v100r006c00 |
| Huawei | Cloudengine 5800 Firmware | v200r001c00 |
| Huawei | Cloudengine 6800 Firmware | v100r003c00 |
| Huawei | Cloudengine 6800 Firmware | v100r005c00 |
| Huawei | Cloudengine 6800 Firmware | v100r005c10 |
| Huawei | Cloudengine 6800 Firmware | v100r006c00 |
| Huawei | Cloudengine 6800 Firmware | v200r001c00 |
| Huawei | Cloudengine 7800 Firmware | v100r003c00 |
| Huawei | Cloudengine 7800 Firmware | v100r005c00 |
| Huawei | Cloudengine 7800 Firmware | v100r005c10 |
| Huawei | Cloudengine 7800 Firmware | v100r006c00 |
| Huawei | Cloudengine 7800 Firmware | v200r001c00 |
| Huawei | Cloudengine 8800 Firmware | v100r006c00 |
| Huawei | Cloudengine 8800 Firmware | v200r001c00 |
| Huawei | E600 Firmware | v200r008c00 |
| Huawei | S12700 Firmware | v200r005c00 |
| Huawei | S12700 Firmware | v200r006c00 |
| Huawei | S12700 Firmware | v200r007c00 |
| Huawei | S12700 Firmware | v200r008c00 |
| Huawei | S1700 Firmware | v100r006c00 |
| Huawei | S1700 Firmware | v100r007c00 |
| Huawei | S1700 Firmware | v200r006c00 |
| Huawei | S2300 Firmware | v100r005c00 |
| Huawei | S2300 Firmware | v100r006c00 |
| Huawei | S2300 Firmware | v100r006c03 |
| Huawei | S2300 Firmware | v100r006c05 |
| Huawei | S2300 Firmware | v200r003c00 |
| Huawei | S2300 Firmware | v200r003c02 |
| Huawei | S2300 Firmware | v200r003c10 |
| Huawei | S2300 Firmware | v200r005c00 |
| Huawei | S2300 Firmware | v200r005c01 |
| Huawei | S2300 Firmware | v200r005c02 |
| Huawei | S2300 Firmware | v200r005c03 |
| Huawei | S2300 Firmware | v200r006c00 |
| Huawei | S2300 Firmware | v200r007c00 |
Showing 50 of 143 affected configurations. See NVD for the full list.
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170720-01-ospf-enIssue Tracking, Mitigation, Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170720-01-ospf-enIssue Tracking, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8147?
How severe is CVE-2017-8147?
How do I fix CVE-2017-8147?
Are you affected by CVE-2017-8147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
