| Summary | Huawei AR120-S V200R006C10, V200R007C00, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C02, AR1200-S V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C02, AR150-S V200R006C10, V200R007C00, AR160 V200R006C10, V200R006C12, V200R007C00S, V200R007C02, AR200 V200R006C10, V200R007C00, AR200-S V200R006C10, V200R007C00, AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C02, AR2200-S V200R006C10, V200R007C00, V200R008C20, AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C02, AR3600 V200R006C10, V200R007C00, AR510 V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, IPS Module V500R001C30, NIP6300 V500R001C30, NetEngine16EX V200R006C10, V200R007C00 have an insufficient input validation vulnerability. An unauthenticated, remote attacker may send crafted IKE V2 messages to the affected products. Due to the insufficient validation of the messages, successful exploit will cause invalid memory access and result in a denial of service on the affected products. |
|---|---|
| Publication Date | Feb. 16, 2018, 1:29 a.m. |
| Registration Date | Jan. 26, 2021, 1:19 p.m. |
| Last Update | Nov. 21, 2024, 12:17 p.m. |
| CVSS3.0 : HIGH | |
| スコア | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 不要 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 高 |
| CVSS2.0 : MEDIUM | |
| Score | 5.0 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 不要 |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 低 |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar120-s:-:*:*:*:*:*:*:* | ||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar1200_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar1200_firmware:v200r006c13:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar1200_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar1200_firmware:v200r007c02:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar1200:-:*:*:*:*:*:*:* | ||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar1200-s_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar1200-s_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar1200-s_firmware:v200r008c20:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar1200-s:-:*:*:*:*:*:*:* | ||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar150_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar150_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar150_firmware:v200r007c02:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar150:-:*:*:*:*:*:*:* | ||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar150-s_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar150-s_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar150-s:-:*:*:*:*:*:*:* | ||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar160_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar160_firmware:v200r006c12:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar160_firmware:v200r007c00s:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar160_firmware:v200r007c02:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar160:-:*:*:*:*:*:*:* | ||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar200_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar200_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar200:-:*:*:*:*:*:*:* | ||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar200-s_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar200-s_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar200-s:-:*:*:*:*:*:*:* | ||||
| Configuration9 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar2200_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200_firmware:v200r006c13:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200_firmware:v200r006c16:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200_firmware:v200r007c02:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar2200:-:*:*:*:*:*:*:* | ||||
| Configuration10 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar2200-s_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200-s_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar2200-s_firmware:v200r008c20:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar2200-s:-:*:*:*:*:*:*:* | ||||
| Configuration11 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar3200_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar3200_firmware:v200r006c11:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar3200_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar3200_firmware:v200r007c02:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar3200:-:*:*:*:*:*:*:* | ||||
| Configuration12 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar3600_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar3600_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar3600:-:*:*:*:*:*:*:* | ||||
| Configuration13 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ar510_firmware:v200r006c12:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar510_firmware:v200r006c13:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar510_firmware:v200r006c15:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar510_firmware:v200r006c16:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar510_firmware:v200r006c17:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:ar510_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ar510:-:*:*:*:*:*:*:* | ||||
| Configuration14 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:ips_module_firmware:v500r001c30:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:* | ||||
| Configuration15 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:nip6300_firmware:v500r001c30:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:* | ||||
| Configuration16 | or higher | or less | more than | less than | |
| cpe:2.3:o:huawei:netengine16ex_firmware:v200r006c10:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:huawei:netengine16ex_firmware:v200r007c00:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:huawei:netengine16ex:-:*:*:*:*:*:*:* | ||||
| Title | 複数の Huawei 製品における入力確認に関する脆弱性 |
|---|---|
| Summary | 複数の Huawei 製品には、入力確認に関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Dec. 15, 2017, midnight |
| Registration Date | March 27, 2018, 5:08 p.m. |
| Last Update | March 27, 2018, 5:08 p.m. |
| Huawei |
| AR120-S ファームウェア |
| AR1200 ファームウェア |
| AR1200-S ファームウェア |
| AR150 ファームウェア |
| AR150-S ファームウェア |
| AR160 ファームウェア |
| AR200 ファームウェア |
| AR200-S ファームウェア |
| AR2200 ファームウェア |
| AR2200-S ファームウェア |
| AR3200 ファームウェア |
| AR3600 ファームウェア |
| AR510 ファームウェア |
| IPS Module ファームウェア |
| NetEngine16EX ファームウェア |
| NIP6300 ファームウェア |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2018年03月27日] 掲載 |
March 27, 2018, 5:08 p.m. |