Vulnerability Details CVE-2018-7994
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability. The software does not release allocated memory properly when processing Protal questionnaire. A remote attacker could send a lot questionnaires to the device, successful exploit could cause the device to reboot since running out of memory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.8
Products affected by CVE-2018-7994
-
cpe:2.3:h:huawei:ips_module:-
-
cpe:2.3:h:huawei:ngfw_module:-
-
cpe:2.3:h:huawei:nip6300:-
-
cpe:2.3:h:huawei:nip6600:-
-
cpe:2.3:h:huawei:nip6800:-
-
cpe:2.3:h:huawei:secospace_usg6600:-
-
cpe:2.3:h:huawei:usg9500:-
-
cpe:2.3:o:huawei:ips_module:v500r001c50
-
cpe:2.3:o:huawei:ngfw_module:v500r001c50
-
cpe:2.3:o:huawei:ngfw_module:v500r002c10
-
cpe:2.3:o:huawei:nip6300:v500r001c50
-
cpe:2.3:o:huawei:nip6600:v500r001c50
-
cpe:2.3:o:huawei:nip6800:v500r001c50
-
cpe:2.3:o:huawei:secospace_usg6600:v500r001c50
-
cpe:2.3:o:huawei:usg9500:v500r001c50