VYPR
Unrated severityNVD Advisory· Published Feb 15, 2018· Updated Aug 5, 2024

CVE-2017-17299

CVE-2017-17299

Description

Huawei AR120-S V200R006C10, V200R007C00, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C02, AR1200-S V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C02, AR150-S V200R006C10, V200R007C00, AR160 V200R006C10, V200R006C12, V200R007C00S, V200R007C02, AR200 V200R006C10, V200R007C00, AR200-S V200R006C10, V200R007C00, AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C02, AR2200-S V200R006C10, V200R007C00, V200R008C20, AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C02, AR3600 V200R006C10, V200R007C00, AR510 V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, IPS Module V500R001C30, NIP6300 V500R001C30, NetEngine16EX V200R006C10, V200R007C00 have an insufficient input validation vulnerability. An unauthenticated, remote attacker may send crafted IKE V2 messages to the affected products. Due to the insufficient validation of the messages, successful exploit will cause invalid memory access and result in a denial of service on the affected products.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated IKE V2 messages cause memory corruption and denial of service on Huawei AR, NIP, and NetEngine routers.

Vulnerability

An insufficient input validation vulnerability exists in the IKE V2 message handling of multiple Huawei products, including AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR3600, AR510, IPS Module V500R001C30, NIP6300 V500R001C30, and NetEngine16EX. The affected versions include V200R006C10, V200R006C11, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R007C00S, V200R007C02, V200R008C20, and others as listed in the advisory [1]. An unauthenticated, remote attacker can send crafted IKE V2 messages to the device, and due to incomplete validation, the messages trigger invalid memory access, leading to a denial of service.

Exploitation

An attacker does not require any prior authentication or network proximity beyond IP connectivity to the target device. The attacker crafts specific IKE V2 packets and sends them to the affected Huawei product. The software lacks proper input validation on these messages, so processing them causes an invalid memory access condition. No user interaction or special privileges are needed [1].

Impact

Successful exploitation results in a denial of service. The invalid memory access disrupts device operation, potentially causing crashes or service interruptions on the router or network security appliance. Confidentiality and integrity are not directly compromised according to the advisory [1].

Mitigation

Huawei has released software updates to fix this vulnerability. The resolved versions are listed per product in the advisory; for example, AR120-S V200R006C10SPC300 is resolved in V200R008SPH003. The advisory was published 2017-12-15 and updated 2020-09-16 [1]. Users should upgrade to the specified resolved versions or later. If upgrading is not possible, applying access control lists to restrict IKE V2 traffic from untrusted sources may reduce risk until a patch can be applied.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Huawei/AR120-Sllm-fuzzy
    Range: V200R006C10, V200R007C00
  • Huawei/AR1200llm-fuzzy
    Range: V200R006C10, V200R006C13, V200R007C00, V200R007C02
  • Range: V500R001C30
  • Huawei Technologies Co., Ltd./AR120-S,AR1200,AR1200-S,AR150,AR150-S,AR160,AR200,AR200-S,AR2200,AR2200-S,AR3200,AR3600,AR510,IPS Module,NIP6300,NetEngine16EXv5
    Range: AR120-S V200R006C10, V200R007C00, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C02, AR1200-S V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C02, AR150-S V200R006C10, V200R007C00, AR160 V200R006C10, V200R006C12, V200R007C00S, V200R007C02, AR200 V200R006C10, V200R007C00, AR200-S V200R006C10, V200R007C00, AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C02, AR2200-S V200R006C10, V200R007C00, V200R008C20, AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C02, AR3600 V200R006C10, V200R007C00, AR510 V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, IPS Module V500R001C30, NIP6300 V500R001C30, NetEngine16EX V200R006C10, V200R007C00

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.