CVE-2017-15346
Description
XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C02, V200R008C00, V200R009C00, V200R010C00,S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,eCNS210_TD V100R004C10, V100R004C10SPC003, V100R004C10SPC100, V100R004C10SPC101, V100R004C10SPC102, V100R004C10SPC200, V100R004C10SPC221, V100R004C10SPC400 has a DOS vulnerability. An attacker may craft specific XML files to the affected products. Due to not check the specially XML file and to parse this file, successful exploit will result in DOS attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A DoS vulnerability in Huawei product XML parser allows crafted XML files to cause denial of service.
Vulnerability
The XML parser in multiple Huawei products, including S12700 V200R005C00, S1700 V200R009C00, V200R010C00, and many others, has a denial of service vulnerability. The parser fails to properly validate specially crafted XML files, leading to a crash or hang. Affected versions are listed in the advisory [1].
Exploitation
An attacker can exploit this vulnerability by sending a specially crafted XML file to the affected product. No authentication is required, and the attack can be launched remotely over the network.
Impact
Successful exploitation results in a denial of service, causing the product to become unresponsive or crash. This can disrupt normal operations.
Mitigation
Huawei has released software updates to fix these vulnerabilities. Customers should upgrade to the resolved versions specified in the advisory [1]. For example, S12700 should upgrade to V2R11C10. No workaround is available, but the patches address the issue.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: V100R004C10, V100R004C10SPC003, V100R004C10SPC100, V100R004C10SPC101, V100R004C10SPC102, V100R004C10SPC200, V100R004C10SPC221, V100R004C10SPC400
- Huawei Technologies Co., Ltd./S12700, S1700,S3700,S5700,S6700,S7700, S9700, eCNS210_TDv5Range: S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C02, V200R008C00, V200R009C00, V200R010C00,S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,eCNS210_TD V100R004C10, V100R004C10SPC003, V100R004C10SPC100, V100R004C10SPC101, V100R004C10SPC102, V100R004C10SPC200, V100R004C10SPC221, V100R004C10SPC400,
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20171201-01-xml-enmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.