Huawei router VPN route forwarding jump Vulnerability (CVE-2015-8087)
Huawei router VPN route forwarding jump Vulnerability (CVE-2015-8087)
Release date:
Updated on:
Affected Systems:
Huawei NE series router NE80E
Huawei NE series router NE40E-M2
Huawei NE series router NE40E-M
Huawei NE series router NE40E
Huawei NE series router NE20E-S
Description:
CVE (CAN) ID: CVE-2015-8087
Huawei NE series routers are Huawei's high-end router products for carrier data communication networks.
Huawei NE20E-S, NE40E-M, NE40E-M2 router (earlier than V800R007C10SPC100) and NE40E, NE80E router (earlier than V800R007C00SPC100) has VPN routing and forwarding jump vulnerability, through the construction of MPLS Forwarding packet, remote attackers can launch flood attacks on the target VPN.
<* Source: Huawei
*>
Suggestion:
Vendor patch:
Huawei
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.huawei.com/en/security/psirt/report-vulnerabilities/index.htm
Http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-457933.htm
This article permanently updates the link address: