VYPR
Unrated severityNVD Advisory· Published Feb 15, 2018· Updated Aug 5, 2024

CVE-2017-15336

CVE-2017-15336

Description

The SIP backup feature in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6800 V500R001C50, RP200 V500R002C00, V600R006C00, SVN5600 V200R003C00, V200R003C10, SVN5800 V200R003C00, V200R003C10, SVN5800-C V200R003C00, V200R003C10, SeMG9811 V300R001C01, Secospace USG6300 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V100R001C00, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, TE30 V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002C00, V600R006C00, USG9500 V500R001C00, V500R001C20, V500R001C30, USG9520 V300R001C01, V300R001C20, USG9560 V300R001C01, V300R001C20, USG9580 V300R001C01, V300R001C20, VP9660 V200R001C02, V200R001C30, V500R002C00, V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02, V100R011C03, eSpace U1981 V100R001C20, V200R003C00, V200R003C20, V200R003C30 has a buffer overflow vulnerability. An attacker may send specially crafted messages to the affected products. Due to the insufficient validation of some values for SIP messages, successful exploit may cause services abnormal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in the SIP backup feature of many Huawei products allows remote attackers to cause service abnormalities via crafted SIP messages.

Vulnerability

A buffer overflow vulnerability exists in the SIP backup feature of multiple Huawei products, including DP300 V500R002C00, IPS Module V100R001C10 through V500R001C50, NGFW Module V100R001C10 through V500R002C10, NIP6300/6600/6800 V500R001C00 through V500R001C50, RP200 V500R002C00/V600R006C00, SVN5600/5800/5800-C V200R003C00/V200R003C10, SeMG9811 V300R001C01, Secospace USG6300/6500/6600 V100R001C10 through V500R001C50, TE30 V100R001C02/V100R001C10/V500R002C00/V600R006C00, TE40/50 V500R002C00/V600R006C00, TE60 V100R001C01/V100R001C10/V500R002C00/V600R006C00, USG9500 V500R001C00 through V500R001C30, USG9520/9560/9580 V300R001C01/V300R001C20, VP9660 V200R001C02 through V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02/V100R011C03, and eSpace U1981 V100R001C20 through V200R003C30. The flaw stems from insufficient validation of certain values in SIP messages, allowing a crafted packet to trigger a buffer overflow on the affected device [1].

Exploitation

An attacker must send specially crafted SIP messages to an affected product over the network. No authentication or user interaction is required, as the vulnerability is reachable through the SIP backup feature's message parsing routine. The attacker crafts messages containing oversized or malformed values that exceed the buffer capacity, causing the overflow [1].

Impact

Successful exploitation causes the affected product's services to become abnormal, potentially leading to denial of service (DoS). The advisory does not indicate arbitrary code execution; the primary outcome is disruption of SIP-based functionality [1].

Mitigation

Huawei released software updates to fix this vulnerability as of December 1, 2017. Users should upgrade to the resolved product versions listed in Huawei's security advisory (huawei-sa-20171201-01-sip) [1]. No workaround is documented; patching is the only recommended mitigation.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Huawei/DP300llm-fuzzy
    Range: = V500R002C00
  • Range: = V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50
  • Range: = V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10
  • Huawei Technologies Co., Ltd./DP300,IPS Module,NGFW Module,NIP6300,NIP6600,NIP6800,RP200,SVN5600,SVN5800,SVN5800-C,SeMG9811,Secospace USG6300,Secospace USG6500,Secospace USG6600,TE30,TE40,TE50,TE60,USG9500,USG9520,USG9560,USG9580,VP9660,ViewPoint 8660,ViewPoint 9030,eSpace U1981v5
    Range: DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6800 V500R001C50, RP200 V500R002C00, V600R006C00, SVN5600 V200R003C00, V200R003C10, SVN5800 V200R003C00, V200R003C10, SVN5800-C V200R003C00, V200R003C10, SeMG9811 V300R001C01, Secospace USG6300 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V100R001C00, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, TE30 V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C01, V100R001C10, V500R002 ...[truncated*]

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.