CVE Vulnerabilities

CVE-2017-17131

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Mar 05, 2018 | Modified: Oct 03, 2019
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
6.3 MEDIUM
AV:N/AC:M/Au:S/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded. An authenticated remote attacker can place a malformed putty key file in system when a system manager load the key an infinite loop happens which lead to reboot the system.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Dp300_firmware Huawei v500r002c00 (including) v500r002c00 (including)

References