Vulnerability Name:

CVE-2016-6901 (CCN-117333)

Assigned:2016-08-24
Published:2016-08-24
Updated:2016-09-28
Summary:Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service via format string specifiers in vectors involving partial commands.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2016-6901

Source: CCN
Type: huawei-sa-20160824-01-vrp
Uncontrolled Format String Vulnerability on Multiple Products

Source: CONFIRM
Type: Vendor Advisory
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-vrp-en

Source: BID
Type: Third Party Advisory, VDB Entry
92618

Source: CCN
Type: BID-92618
Multiple Huawei Products CVE-2016-6901 Remote Format String Vulnerability

Source: XF
Type: UNKNOWN
huawei-routers-cve20166901-dos(117333)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:huawei:ar_firmware:v200r005:*:*:*:*:*:*:*
  • OR cpe:/o:huawei:ar_firmware:v200r006:*:*:*:*:*:*:*
  • OR cpe:/o:huawei:ar_firmware:v200r007c00:*:*:*:*:*:*:*
  • AND
  • cpe:/h:huawei:ar100:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar120:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar1200:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar150:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar200:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar2200:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar2500:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar3200:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar3600:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar500:-:*:*:*:*:*:*:*
  • OR cpe:/h:huawei:ar550:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:huawei:netengine_16ex_firmware:v200r005:*:*:*:*:*:*:*
  • OR cpe:/o:huawei:netengine_16ex_firmware:v200r006:*:*:*:*:*:*:*
  • OR cpe:/o:huawei:netengine_16ex_firmware:v200r007c00:*:*:*:*:*:*:*
  • AND
  • cpe:/h:huawei:netengine_16ex:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    huawei ar firmware v200r005
    huawei ar firmware v200r006
    huawei ar firmware v200r007c00
    huawei ar100 -
    huawei ar120 -
    huawei ar1200 -
    huawei ar150 -
    huawei ar200 -
    huawei ar2200 -
    huawei ar2500 -
    huawei ar3200 -
    huawei ar3600 -
    huawei ar500 -
    huawei ar550 -
    huawei netengine 16ex firmware v200r005
    huawei netengine 16ex firmware v200r006
    huawei netengine 16ex firmware v200r007c00
    huawei netengine 16ex -