CVE-2018-7994
published 2018-07-31CVE-2018-7994: Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace…
high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | ips_module | — | — |
| huawei | ngfw_module | — | — |
| huawei | ngfw_module | — | — |
| huawei | nip6300 | — | — |
| huawei | nip6600 | — | — |
| huawei | nip6800 | — | — |
| huawei | secospace_usg6600 | — | — |
| huawei | usg9500 | — | — |