CVE-2017-15344 Details
Description
Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-02-sctp-en | CVE | Vendor Advisory |
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-02-sctp-en | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| huawei ar120-s firmware | v200r006c10 v200r007c00 v200r008c20 v200r008c30 |
CPE
Remediation
| |
| huawei ar1200 firmware | v200r007c01 v200r007c02 |
CPE
Remediation
| |
| huawei ar3200 firmware | v200r006c11 v200r008c00 v200r008c10 |
CPE
Remediation
| |
| huawei ar3200 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 22, 2018 | Initial Analysis | [email protected] |