CVE-2018-7994
Last modified
CVE-2018-7994 is a vulnerability of currently unknown severity. Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. EPSS estimates a 1.32% chance of exploitation in the next 30 days.
Description
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ips Module | v500r001c50 |
| Huawei | Ngfw Module | v500r001c50 |
| Huawei | Ngfw Module | v500r002c10 |
| Huawei | Nip6300 | v500r001c50 |
| Huawei | Nip6600 | v500r001c50 |
| Huawei | Nip6800 | v500r001c50 |
| Huawei | Secospace Usg6600 | v500r001c50 |
| Huawei | Usg9500 | v500r001c50 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7994?
How severe is CVE-2018-7994?
How do I fix CVE-2018-7994?
Are you affected by CVE-2018-7994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
