CVE-2017-17318
Status: ModifiedMedium (6.5)—
Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http request to device, the webserver process will try to apply too much memory which can cause the device to become unable to respond. An attacker can launch a DoS attack by exploiting this vulnerability.
CVSS
- Version: 3.0
- Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.36%
- Percentile among all scored CVEs: 28
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-20
References
Raw JSON (NVD)
Show
{
"id": "CVE-2017-17318",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.1,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "Huawei Technologies Co., Ltd.",
"product": "E5771h-937",
"versions": [
{
"status": "affected",
"version": "E5771h-937, The versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and The versions before E5771h-937TCPU-V200R001B329D05SP00C1308"
}
]
}
]
}
],
"published": "2018-04-30T14:29:00.267",
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180428-01-mbb-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180428-01-mbb-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http request to device, the webserver process will try to apply too much memory which can cause the device to become unable to respond. An attacker can launch a DoS attack by exploiting this vulnerability."
},
{
"lang": "es",
"value": "Los productos Huawei MBB (Mobile Broadband) E5771h-937 en versiones anteriores a la E5771h-937TCPU-V200R001B328D62SP00C1133 y versiones anteriores a la E5771h-937TCPU-V200R001B329D05SP00C1308 tienen una vulnerabilidad de denegación de servicio (DoS). Cuando un atacante que accede al dispositivo envía una petición http especial al dispositivo, el proceso webserver intentará aplicar demasiada memoria, lo que puede hacer que el dispositivo deje de responder. Un atacante puede iniciar un ataque de denegación de servicio (DoS) explotando esta vulnerabilidad."
}
],
"lastModified": "2026-06-17T01:10:41.367",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:e5771h-937_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F84E369-96ED-4A13-AE99-2895FB270992",
"versionEndExcluding": "v200r001b329d05sp00c1308"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:e5771h-937:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "74BB197F-7CBE-4EA1-8172-192DFFCD2FDB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:e5771h-937_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4CB19716-C380-4B72-8559-592533FC35EC",
"versionEndExcluding": "v200r001b328d62sp00c1133"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:e5771h-937:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "74BB197F-7CBE-4EA1-8172-192DFFCD2FDB"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}