Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Huawei Data Communication: Two DOS Vulnerabilities of XML Parser in Some Huawei Products (huawei-sa-20171201-01-xml)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
XML parser have two DOS vulnerabilities in some Huawei products.
Insight
Insight
XML parser have two DOS vulnerabilities in some Huawei products. An attacker may craft specific XML files to the affected products. Due to not check the specially XML file and to parse this file, successful exploit will result in DOS attacks. (Vulnerability ID: HWPSIRT-2017-03037 and HWPSIRT-2017-03038)Huawei has released software updates to fix these vulnerabilities. This advisory is available in the linked references.
Affected Software
Affected Software
DBS3900 TDD LTE versions V100R003C00 V100R004C10 S12700 versions V200R005C00 S1700 versions V200R009C00 V200R010C00 S2300 versions V100R006C03 V100R006C05 V200R003C00 V200R005C00 V200R006C00 V200R007C00 V200R008C00 V200R009C00 V200R010C00 S3300 versions V100R006C03 V100R006C05 S3700 versions V100R006C03 V100R006C05 S5300 versions V200R001C00 V200R003C00 V200R003C02 V200R005C00 V200R005C03 V200R005C05 V200R006C00 V200R007C00 V200R008C00 V200R009C00 V200R010C00 S5700 versions V200R001C00 V200R002C00 V200R003C00 V200R003C02 V200R005C00 V200R006C00 V200R007C00 V200R008C00 V200R009C00 V200R010C00 S600-E versions V200R008C00 V200R009C00 V200R010C00 S6300 versions V200R001C00 V200R003C00 V200R005C00 V200R005C02 V200R007C00 V200R008C00 V200R009C00 V200R010C00 S6700 versions V200R001C00 V200R002C00 V200R003C00 V200R005C00 V200R005C02 V200R008C00 V200R009C00 V200R010C00 S7700 versions V200R001C00 V200R002C00 V200R003C00 V200R005C00 V200R006C00 V200R007C00 V200R008C00 V200R009C00 V200R010C00 S9300 versions V200R001C00 V200R003C00 V200R005C00 V200R006C00 V200R007C00 V200R008C00 V200R009C00 S9700 versions V200R001C00 V200R002C00 V200R003C00 V200R005C00 V200R006C00 V200R007C00 V200R008C00 V200R009C00 V200R010C00 eCNS210_TD versions V100R004C10 V100R004C10SPC003 V100R004C10SPC100 V100R004C10SPC101 V100R004C10SPC102 V100R004C10SPC200 V100R004C10SPC221 V100R004C10SPC400
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
See the referenced vendor advisory for a solution.