CVE-2017-15344: Huawei AR120-S Firmware

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has an integer overflow vulnerability. The software does not sufficiently validate certain field in SCTP messages, a remote unauthenticated attacker could send a crafted SCTP message to the device. Successful exploit could cause system reboot.

Affected products

  • Huawei AR120-S Firmware: version v200r006c10 only; version v200r007c00 only; version v200r008c20 only; version v200r008c30 only
  • Huawei AR1200 Firmware: version v200r007c01 only; version v200r007c02 only
  • Huawei AR3200 Firmware: version v200r006c11 only; version v200r008c00 only; version v200r008c10 only

Published 2018-02-15. Last modified 2026-06-17.