CVE-2016-8802

The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200 allows authenticated attackers to setup a specific security policy into the devices, causing a buffer overflow and crashing the system.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c20spc100:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c20spc101:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c20spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c20spc100:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c20spc101:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c20spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:secospace_usg6500:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c20spc100:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c20spc101:*:*:*:*:*:*:*
cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c20spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:00

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161125-01-usg-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161125-01-usg-en - Vendor Advisory
References () http://www.securityfocus.com/bid/94538 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94538 - Third Party Advisory, VDB Entry

Information

Published : 2017-04-02 20:59

Updated : 2024-11-21 03:00


NVD link : CVE-2016-8802

Mitre link : CVE-2016-8802

CVE.ORG link : CVE-2016-8802


JSON object : View

Products Affected

huawei

  • secospace_usg6300_firmware
  • secospace_usg6300
  • secospace_usg6500_firmware
  • secospace_usg6500
  • secospace_usg6600
  • secospace_usg6600_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer