CVE-2018-7994

Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:ips_module:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:huawei:ngfw_module:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ngfw_module:v500r002c10:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:nip6300:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:nip6600:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:nip6800:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:secospace_usg6600:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:usg9500:v500r001c50:*:*:*:*:*:*:*
cpe:2.3:h:huawei:usg9500:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:13

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-firewall-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-firewall-en - Vendor Advisory

Information

Published : 2018-07-31 14:29

Updated : 2024-11-21 04:13


NVD link : CVE-2018-7994

Mitre link : CVE-2018-7994

CVE.ORG link : CVE-2018-7994


JSON object : View

Products Affected

huawei

  • nip6300
  • usg9500
  • nip6600
  • secospace_usg6600
  • nip6800
  • ips_module
  • ngfw_module
CWE
CWE-772

Missing Release of Resource after Effective Lifetime