CVE-2015-8676
CVSS V2 High 7.8
CVSS V3 High 7.5
Description
Memory leak in Huawei S5300EI, S5300SI, S5310HI, S6300EI/ S2350EI, and S5300LI Campus series switches with software V200R001C00 before V200R001SPH018, V200R002C00 before V200R003SPH011, and V200R003C00 before V200R003SPH011; S9300, S7700, and S9700 Campus series switches with software V200R001C00 before V200R001SPH023, V200R002C00 before V200R003SPH011, and V200R003C00 before V200R003SPH011; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote attackers to cause a denial of service (memory consumption and reboot) via a large number of ICMPv6 packets.
Overview
- CVE ID
- CVE-2015-8676
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2016-04-14T15:59:02
- Last Modified Date
- 2019-06-20T13:54:56
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
AND | ||||
cpe:2.3:o:huawei:s2350ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s2350ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s2350ei:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s5300ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s5300ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s5300ei:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s5300si_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s5300si_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s5300si:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s5310hi_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s5310hi_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s5310hi:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s6300ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s6300ei_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s6300ei:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s5300li_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph018 |
cpe:2.3:o:huawei:s5300li_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003sph011 |
cpe:2.3:h:huawei:s5300li:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s9300_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph023 |
cpe:2.3:o:huawei:s9300_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003c00 |
cpe:2.3:o:huawei:s9300_firmware:v200r003c00:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:h:huawei:s9300:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s7700_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph023 |
cpe:2.3:o:huawei:s7700_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003c00 |
cpe:2.3:o:huawei:s7700_firmware:v200r003c00:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:h:huawei:s7700:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s9700_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r001c00 | v200r001sph023 |
cpe:2.3:o:huawei:s9700_firmware:*:*:*:*:*:*:*:* | 1 | OR | v200r002c00 | v200r003c00 |
cpe:2.3:o:huawei:s9700_firmware:v200r003c00:*:*:*:*:*:*:* | 1 | OR | ||
cpe:2.3:h:huawei:s9700:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s2300_firmware:*:*:*:*:*:*:*:* | 1 | OR | v100r006c05 | v100r006sph022 |
cpe:2.3:h:huawei:s2300:-:*:*:*:*:*:*:* | 0 | OR | ||
AND | ||||
cpe:2.3:o:huawei:s3300_firmware:*:*:*:*:*:*:*:* | 1 | OR | v100r006c05 | v100r006sph022 |
cpe:2.3:h:huawei:s3300:-:*:*:*:*:*:*:* | 0 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:N/AC:L/Au:N/C:N/I:N/A:C
- Access Vector
- NETWORK
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- NONE
- Integrity Impact
- NONE
- Availability Impact
- COMPLETE
- Base Score
- 7.8
- Severity
- HIGH
- Exploitability Score
- 10
- Impact Score
- 6.9
CVSS Version 3
- Version
- 3.0
- Vector String
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Vector
- NETWORK
- Attack Compatibility
- LOW
- Privileges Required
- NONE
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- NONE
- Availability Impact
- HIGH
- Base Score
- 7.5
- Base Severity
- HIGH
- Exploitability Score
- 3.9
- Impact Score
- 3.6
References
Reference URL | Reference Tags |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160113-02-switch-en | Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2015-8676 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8676 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 07:49:53 | Added to TrackCVE | |||
2022-12-02 09:00:11 | 2016-04-14T15:59Z | 2016-04-14T15:59:02 | CVE Published Date | updated |
2022-12-02 09:00:11 | 2019-06-20T13:54:56 | CVE Modified Date | updated | |
2022-12-02 09:00:11 | Analyzed | Vulnerability Status | updated |