« Back to list

CVE-2017-15344

Status: ModifiedHigh (7.5)—

Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-15344",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei Technologies Co., Ltd.",
          "product": "AR3200",
          "versions": [
            {
              "status": "affected",
              "version": "V200R006C10,V200R006C11,V200R007C00,V200R007C01,V200R007C02,V200R008C00,V200R008C10,V200R008C20,V200R008C30"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-02-15T16:29:00.953",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-02-sctp-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-02-sctp-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot."
    },
    {
      "lang": "es",
      "value": "Huawei AR3200 con software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20 y V200R008C30 tiene una vulnerabilidad de desbordamiento de enteros. El software no valida suficientemente ciertos campos en los mensajes SCTP, por lo que un atacante remoto no autenticado podría enviar un mensaje SCTP manipulado al dispositivo. Una explotación con éxito podría provocar el rearranque del sistema."
    }
  ],
  "lastModified": "2026-06-17T01:07:38.433",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9EC3BAF-54F8-4EEC-A99B-D8BD458EE638"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5DD9E894-321E-4A61-9DA6-677042DDD739"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar120-s_firmware:v200r008c20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79DA91B4-77A6-4A37-8799-5E548184D49C"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar120-s_firmware:v200r008c30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42376C56-573F-4A88-B18E-43F636B17B41"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar1200_firmware:v200r007c01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "334E0095-CF32-497D-85AC-AE8AEDE4EC50"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar1200_firmware:v200r007c02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4459EF03-890E-446E-8702-8F7CE499FB48"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar3200_firmware:v200r006c11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8BE6310-A42C-4BB3-BB02-7CE6F4FF340D"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar3200_firmware:v200r008c00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A842B77-C902-4B20-A171-3F98C75E6160"
            },
            {
              "criteria": "cpe:2.3:o:huawei:ar3200_firmware:v200r008c10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC61DFB2-E24C-4148-892E-A14F1EC3F9CA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:ar3200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9309E1AA-0C4E-422C-9307-A8DD0AE5D576"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}