CVE-2016-8782 Information

Description

Huawei CloudEngine 12800 V100R003C00 V100R003C10 V100R005C00 V100R005C10 V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices repeatedly. Due to improper validation of some specific fields of the packet the LDP processing module does not release the memory resulting in memory leak.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Reference

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161214-01-ldp-en http://www.securityfocus.com/bid/94941

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

5.3

Share on: