CVE-2016-8785

Severity
4.3MEDIUM
EPSS
0.1%
top 71.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMay 14

Description

Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory data and possibly leading to sensitive information leakage.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

NVDhuawei/s5700_firmwarev200r007c00
NVDhuawei/s7700_firmware5 versions+4
NVDhuawei/s9700_firmwarev200r007c00
NVDhuawei/s12700_firmwarev200r007c00, v200r008c00+1

🔴Vulnerability Details

3
GHSA
GHSA-w6f4-9255-g83f: Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 ha2022-05-14
CVEList
CVE-2016-8785: Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 ha2018-03-09
OSV
linux-lts-utopic vulnerabilities2016-02-22
CVE-2016-8785 (MEDIUM CVSS 4.3) | Huawei S12700 V200R007C00 | cvebase.io