{ "CVE_data_meta" : { "ASSIGNER" : "psirt@huawei.com", "ID" : "CVE-2017-17216", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "DP300; RP200; TE30; TE40; TE50; TE60", "version" : { "version_data" : [ { "version_value" : "DP300 V500R002C00" }, { "version_value" : "RP200 V500R002C00SPC200" }, { "version_value" : "V600R006C00" }, { "version_value" : "TE30 V100R001C10" }, { "version_value" : "V500R002C00" }, { "version_value" : "V600R006C00" }, { "version_value" : "TE40 V500R002C00" }, { "version_value" : "V600R006C00" }, { "version_value" : "TE50 V500R002C00" }, { "version_value" : "V600R006C00" }, { "version_value" : "TE60 V100R001C10" }, { "version_value" : "V500R002C00" }, { "version_value" : "V600R006C00" } ] } } ] }, "vendor_name" : "Huawei Technologies Co., Ltd." } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may cause process reboot." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "out-of-bounds read" } ] } ] }, "references" : { "reference_data" : [ { "name" : "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180124-01-mgcp-en", "refsource" : "CONFIRM", "url" : "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180124-01-mgcp-en" } ] } }