cbcvebase.
CVE-2018-7994
published 2018-07-31

CVE-2018-7994: Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.

Affected

8 ranges
VendorProductVersion rangeFixed in
huaweiips_module
huaweingfw_module
huaweingfw_module
huaweinip6300
huaweinip6600
huaweinip6800
huaweisecospace_usg6600
huaweiusg9500