Vulnerability Details CVE-2018-7920
Huawei AR1200 V200R006C10SPC300, AR160 V200R006C10SPC300, AR200 V200R006C10SPC300, AR2200 V200R006C10SPC300, AR3200 V200R006C10SPC300 devices have an improper resource management vulnerability. Due to the improper implementation of ACL mechanism, a remote attacker may send TCP messages to the management interface of the affected device to exploit this vulnerability. Successful exploit could exhaust the socket resource of management interface, leading to a DoS condition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.8%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-7920
-
cpe:2.3:h:huawei:ar1200:-
-
-
-
cpe:2.3:h:huawei:ar2200:-
-
cpe:2.3:h:huawei:ar3200:-
-
cpe:2.3:o:huawei:ar1200_firmware:v200r006c10spc300
-
cpe:2.3:o:huawei:ar160_firmware:v200r006c10spc300
-
cpe:2.3:o:huawei:ar200_firmware:v200r006c10spc300
-
cpe:2.3:o:huawei:ar2200_firmware:v200r006c10spc300
-
cpe:2.3:o:huawei:ar3200_firmware:v200r006c10spc300