« Volver al listado

CVE-2015-7847

Estado: ModificadaMedia (5.5)—

El producto Huawei MBB (Mobile Broadband) E3272s con versiones de software anteriores a E3272s-153TCPU-V200R002B491D09SP00C00 tiene una vulnerabilidad de denegación de servicio (DoS). Un atacante podría enviar un paquete malicioso a la Common Gateway Interface (CGI) de un dispositivo de destino y hacer que falle mientras establece el atributo port, lo que provoca un ataque DoS.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-7847",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "E3272s Versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00",
          "versions": [
            {
              "status": "affected",
              "version": "E3272s Versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-02T20:59:00.780",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/hw-450877",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/hw-450877",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 has a Denial of Service (DoS) vulnerability. An attacker could send a malicious packet to the Common Gateway Interface (CGI) of a target device and make it fail while setting the port attribute, which causes a DoS attack."
    },
    {
      "lang": "es",
      "value": "El producto Huawei MBB (Mobile Broadband) E3272s con versiones de software anteriores a E3272s-153TCPU-V200R002B491D09SP00C00 tiene una vulnerabilidad de denegación de servicio (DoS). Un atacante podría enviar un paquete malicioso a la Common Gateway Interface (CGI) de un dispositivo de destino y hacer que falle mientras establece el atributo port, lo que provoca un ataque DoS."
    }
  ],
  "lastModified": "2026-06-17T00:33:15.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:e3272s_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2923F5D8-7244-4D9E-8AF4-56CC3954C6E3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:e3272s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BC36F20C-F016-46D5-BAC5-74068B378EE6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}