CVE-2017-15314Missing Release of Resource after Effective Lifetime in Huawei Dp300 Firmware

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 93.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 9
Latest updateMay 13

Description

Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE50 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory le

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDhuawei/te30_firmware11 versions+10
NVDhuawei/te40_firmware5 versions+4
NVDhuawei/te50_firmware4 versions+3
NVDhuawei/te60_firmwarev100r001c10, v500r002c00, v600r006c00+2
NVDhuawei/dp300_firmwarev500r002c00

🔴Vulnerability Details

2
GHSA
GHSA-h442-vmwr-rcjg: Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R2022-05-13
CVEList
CVE-2017-15314: Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R2018-03-09
CVE-2017-15314 — Huawei Dp300 Firmware vulnerability | cvebase