VYPR
Unrated severityNVD Advisory· Published Mar 9, 2018· Updated Aug 5, 2024

CVE-2017-17216

CVE-2017-17216

Description

Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability. An unauthenticated, remote attacker crafts malformed packets with specific parameter to the affected products. Due to insufficient validation of packets, successful exploitation may cause process reboot.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated remote attacker can cause a process reboot by sending a crafted malformed MGCP packet to certain Huawei video conferencing products due to an out-of-bounds read.

Vulnerability

An out-of-bounds read vulnerability exists in the Media Gateway Control Protocol (MGCP) implementation of several Huawei video conferencing products. The affected products include DP300 (V500R002C00), RP200 (V500R002C00SPC200, V600R006C00), TE30 (V100R001C10, V500R002C00, V600R006C00), TE40 (V500R002C00, V600R006C00), TE50 (V500R002C00, V600R006C00), and TE60 (V100R001C10, V500R002C00, V600R006C00) [1]. The flaw is triggered when the product receives malformed packets with a specific parameter; due to insufficient packet validation, an out-of-bounds read occurs.

Exploitation

An unauthenticated attacker with network access to the affected product can craft and send malformed MGCP packets containing a specific parameter [1]. No authentication or prior access is required. The attack is remote and does not require user interaction.

Impact

Successful exploitation of this vulnerability causes the affected process to reboot, resulting in a temporary denial of service (availability impact) [1]. The vulnerability does not appear to allow code execution or data disclosure based on the available information.

Mitigation

Huawei has released software updates to address this vulnerability; the resolved versions are: DP300 (V500R002C00SPCb00), RP200 (V600R006C00SPC200), TE30 (V600R006C00SPC200), TE40 (V600R006C00SPC200), TE50 (V600R006C00SPC200), and TE60 (V600R006C00SPC300) [1]. Customers should apply the appropriate firmware upgrade. No workarounds are documented, and this CVE is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Huawei/Te30llm-fuzzy
    Range: V100R001C10, V500R002C00, V600R006C00
  • Huawei/DP300llm-fuzzy
    Range: V500R002C00
  • Huawei/RP200llm-fuzzy
    Range: V500R002C00SPC200, V600R006C00
  • Huawei Technologies Co., Ltd./DP300; RP200; TE30; TE40; TE50; TE60v5
    Range: DP300 V500R002C00

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.