CVE-2015-8677
Description
Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00 before V200R006SPH002; S9300, S7700, and S9700 Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH009, and V200R006C00 before V200R006SPH003; S5720HI and S5720EI Campus series switches with software V200R006C00 before V200R006SPH002; and S2300 and S3300 Campus series switches with software V100R006C05 before V100R006SPH022 allows remote authenticated users to cause a denial of service (memory consumption and device restart) by logging in and out of the (1) HTTPS or (2) SFTP server, related to SSL session information.
Affected products
13- cpe:2.3:o:huawei:s2300_firmware:*:*:*:*:*:*:*:*Range: >=v100r006c05,<v100r006sph022
- cpe:2.3:o:huawei:s2350ei_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
- cpe:2.3:o:huawei:s3300_firmware:*:*:*:*:*:*:*:*Range: >=v100r006c05,<v100r006sph022
- cpe:2.3:o:huawei:s5300ei_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
- cpe:2.3:o:huawei:s5300li_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
- cpe:2.3:o:huawei:s5300si_firmware:*:*:*:*:*:*:*:*Range: >=v200r001c00,<v200r001sph018
- cpe:2.3:o:huawei:s5310hi_firmware:*:*:*:*:*:*:*:*Range: >=v200r001c00,<v200r001sph018
- cpe:2.3:o:huawei:s5720ei_firmware:*:*:*:*:*:*:*:*Range: >=v200r006c00,<v200r006sph002
- cpe:2.3:o:huawei:s5720hi_firmware:*:*:*:*:*:*:*:*Range: >=v200r006c00,<v200r006sph002
- cpe:2.3:o:huawei:s6300ei_firmware:*:*:*:*:*:*:*:*Range: >=v200r001c00,<v200r001sph018
- cpe:2.3:o:huawei:s7700_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
- cpe:2.3:o:huawei:s9300_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
- cpe:2.3:o:huawei:s9700_firmware:*:*:*:*:*:*:*:*Range: >=v200r003c00,<v200r003sph011
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.