CVE-2017-15349: Huawei Cloudengine 12800 Firmware

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Huawei CloudEngine 12800 V100R003C00, V100R005C00, V100R005C10, V100R006C00,CloudEngine 5800 V100R003C00, V100R005C00, V100R005C10, V100R006C00,CloudEngine 6800 V100R003C00, V100R005C00, V100R005C10, V100R006C00,CloudEngine 7800 V100R003C00, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Resource ReServation Protocol (RSVP) packets to the affected products. Due to not release the memory to handle the packets, successful exploit will result in memory leak of the affected products and lead to a DoS condition.

Affected products

  • Huawei Cloudengine 12800 Firmware: version v100r003c00 only; version v100r005c00 only; version v100r005c10 only; version v100r006c00 only
  • Huawei Cloudengine 5800 Firmware: version v100r003c00 only; version v100r005c00 only; version v100r005c10 only; version v100r006c00 only
  • Huawei Cloudengine 6800 Firmware: version v100r003c00 only; version v100r005c00 only; version v100r005c10 only; version v100r006c00 only
  • Huawei Cloudengine 7800 Firmware: version v100r003c00 only; version v100r005c00 only; version v100r005c10 only; version v100r006c00 only

Published 2018-02-15. Last modified 2026-06-17.