CVE-2018-7994
Estado: ModificadaAlta (7.5)—
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.96%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- CWE-772
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-7994",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "Huawei Technologies Co., Ltd.",
"product": "NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6600; USG9500",
"versions": [
{
"status": "affected",
"version": "IPS Module V500R001C50"
},
{
"status": "affected",
"version": "NGFW Module V500R001C50"
},
{
"status": "affected",
"version": "V500R002C10"
},
{
"status": "affected",
"version": "NIP6300 V500R001C50"
},
{
"status": "affected",
"version": "NIP6600 V500R001C50"
},
{
"status": "affected",
"version": "NIP6800 V500R001C50"
},
{
"status": "affected",
"version": "Secospace USG6600 V500R001C50"
},
{
"status": "affected",
"version": "USG9500 V500R001C50"
}
]
}
]
}
],
"published": "2018-07-31T14:29:01.167",
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-firewall-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180704-01-firewall-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-772"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory."
},
{
"lang": "es",
"value": "Algunos productos Huawei IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 tienen una vulnerabilidad de filtrado de memoria. El software no libera la memoria asignada correctamente al procesar el cuestionario Protal. Un atacante remoto podría enviar muchos cuestionarios al dispositivo; su explotación con éxito podría provocar que el dispositivo se reinicie, ya que se quedaría sin memoria."
}
],
"lastModified": "2026-06-17T02:04:02.600",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:ips_module:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FD82635-8B95-498D-8AB7-1254F133B6DB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2BAD43A3-730A-4ABC-89F0-DF93A06AA60F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:ngfw_module:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5314BBA-E919-45C1-BCF5-BC2D07E199CD"
},
{
"criteria": "cpe:2.3:o:huawei:ngfw_module:v500r002c10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C433D71F-2631-458F-ACF3-0134D93D5C01"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "547D4A9A-6B57-4BBA-9FFE-CF50B9AC5DF4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:nip6300:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94B5F4E5-0508-4491-9B84-FFAE79514419"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5E054182-CE33-45E3-8595-159A75BA5162"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:nip6600:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A297C6B-313D-483A-93D0-82DFD66C4FC9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CE8CA649-7AE1-497C-869B-B4DD315F342C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:nip6800:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8103D4D1-C933-4BF4-A0E2-F63C0A63DEAD"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "875441DD-575F-4F4D-A6BD-23C38641D330"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:secospace_usg6600:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52DEBDDA-79D1-4525-A59C-6D725B477FEB"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BE469876-F873-4705-9760-097AE840A818"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:usg9500:v500r001c50:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DCD7D64-F06A-4BA5-92CF-BBD0737E031B"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:usg9500:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B6064BB-5E62-4D70-B933-05B5426EEE9C"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}