vendor:
AR1220
by:
Roberto Paleari
N/A
CVSS
N/A
Memory errors
Unknown
CWE
Product Name: AR1220
Affected Version From: V200R002C02SPC121T
Affected Version To: V200R002C02SPC121T
Patch Exists: Unknown
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unknown
2013
Multiple buffer overflows on Huawei SNMPv3 service
The Huawei SNMPv3 service running on the affected devices is vulnerable to multiple stack-based buffer overflow issues. These vulnerabilities can be exploited by unauthenticated remote attackers. The issues concern Huawei implementation of the SNMPv3 User-based Security Model (USM [1]). Strictly speaking, attackers can overflow the 'AuthoritativeEngineID' and 'UserName' SNMPv3 USM fields. The vulnerabilities we identified can be classified according to the exploitation context: some issues can be triggered only when SNMP debugging is enabled, while others are exploitable in the default device configuration.
Mitigation:
Disable SNMP debugging and configure ACLs to prevent unauthenticated access to the SNMP service.