Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability
Published Mar 9, 2018
3.3
LOWCVSS 3.0
EPSS 0.22%
Description
Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008C30; NGFW Module V500R001C00; V500R001C20; V500R002C00 have a memory leak vulnerability. The software does not release allocated memory properly when parse XML element data. An authenticated attacker could upload a crafted XML file, successful exploit could cause the system service abnormal since run out of memory.
Affected products
-
- Version AR3200 V200R005C32StatusaffectedConstraints-
- Version NGFW Module V500R001C00StatusaffectedConstraints-
- Version V200R006C10StatusaffectedConstraints-
- Version V200R006C11StatusaffectedConstraints-
- Version V200R007C00StatusaffectedConstraints-
- Version V200R007C01StatusaffectedConstraints-
- Version V200R007C02StatusaffectedConstraints-
- Version V200R008C00StatusaffectedConstraints-
- Version V200R008C10StatusaffectedConstraints-
- Version V200R008C20StatusaffectedConstraints-
- Version V200R008C30StatusaffectedConstraints-
- Version V500R001C20StatusaffectedConstraints-
- Version V500R002C00StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Huawei Technologies Co., Ltd. | AR3200; NGFW Module | n/a |
|
Configuration 1
- v200r005c32
- v200r006c10
- v200r006c11
- v200r007c00
- v200r007c01
- v200r007c02
- v200r008c00
- v200r008c10
- v200r008c20
- v200r008c30
Configuration 2
- v500r001c00
- v500r001c20
- v500r002c00
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AV:L/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.22% (0.00218) | 11.07th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.22% (0.00218) | 12.55th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00044) | 12.95th | v3 (v2023.03.01) |
| May 25, 2024 | 0.04% (0.00044) | 12.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.26th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.42% (0.00416) | 10.04th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (1)
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-04-xml-en x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-04-xml-en | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.