Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Huawei VRP Data Communication: MaxAge LSA Vulnerability (huawei-sa-20170720-01-ospf)

Information

Severity

Severity

Medium

Family

Family

Huawei

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

3 years ago

Modified

Modified

3 years ago

Summary

Multiple Huawei products are prone to a MaxAge LSA vulnerability due to an improper OSPF implementation.

Insight

Insight

When the device receives special LSA packets, the LS (Link Status) age would be set to MaxAge, 3600 seconds. An attacker can exploit this vulnerability to poison the route table and launch a DoS attack.

Affected Software

Affected Software

Huawei AC6005, AC6605, AR1200, AR200, AR3200, CloudEngine 12800, CloudEngine 5800, CloudEngine 6800, CloudEngine 7800, CloudEngine 8800, E600, NE20E-S, S12700, S1700, S2300, S2700, S5300, S5700, S6300, S6700, S7700, S9300, S9700 and Secospace USG6600.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

See the referenced vendor advisory for a solution.

Common Vulnerabilities and Exposures (CVE)