CVE-2017-8162 is a Denial of Service (DoS) vulnerability affecting various Huawei AR series routers, NetEngine16EX, SMC2.0, and SRG series devices across multiple software versions. The vulnerability stems from incorrect processing of malformed messages, which an authenticated, remote attacker can exploit by sending specially crafted messages. Successful exploitation leads to a stack overflow, rendering the affected service unavailable. This vulnerability is rated Medium severity with a CVSS score of 6.5. It has a network attack vector and low attack complexity, requiring authenticated access but no user interaction. The primary impact is high availability loss, with no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation in the wild, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion or media coverage, suggesting low public awareness and limited attacker interest to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v200r006c10CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:* | ||
v200r007c00CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:* | ||
v200r008c20CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r008c20:*:*:*:*:*:*:* | ||
v200r008c30CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r008c30:*:*:*:*:*:*:* | ||
v200r006c10CPE matchmatch criteria | cpe:2.3:o:huawei:ar1200_firmware:v200r006c10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.