← Back to CVE List
Vulnerability Intelligence Report

CVE-2016-4576

Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.38%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
huawei nip6300 all
huawei nip6300_firmware v500r001c00
huawei secospace_usg6500 all
huawei secospace_usg6500_firmware v500r001c00
huawei secospace_antiddos8000 all
huawei secospace_antiddos8000_firmware v500r001c00
huawei usg9500 all
huawei usg9500_firmware v500r001c00
huawei secospace_usg6300 all
huawei secospace_usg6300_firmware v500r001c00
huawei ngfw_module all
huawei ngfw_module_firmware v500r001c00
huawei secospace_usg6600 all
huawei secospace_usg6600_firmware v500r001c00
huawei nip6600 all
huawei nip6600_firmware v500r001c00
huawei ips_module all
huawei ips_module_firmware v500r001c00

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.383%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2016-05-11T00:00:00
Published2016-05-23T19:00:00
Patch Date2016-05-11
Last Updated2024-08-06T00:32:26

LINK COPIED TO CLIPBOARD