SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-8570

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with…

MEDIUM 5.3EPSS 0.60%

Does this matter?

Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.

Description

Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with software V200R002, V200R003, V200R005; S12708, S12712 with software V200R005; 5700HI, 5300HI with software V100R006, V200R001, V200R002, V200R003, V200R005; 5710EI, 5310EI with software V200R002, V200R003, V200R005; 5710HI, 5310HI with software V200R003, V200R005; 6700EI, 6300EI with software V200R005 could cause a leak of IP addresses of devices, related to unintended interface support for VRP MPLS LSP Ping.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
huawei/s9300 firmware · huawei/s9303 firmware · huawei/s9306 firmware · huawei/s9312 firmware · huawei/s7700 firmware · huawei/s7703 firmware · huawei/s7706 firmware · huawei/s7712 firmware · huawei/s9300e firmware · huawei/s9303e firmware · huawei/s9306e firmware · huawei/s9312e firmware · huawei/s9700 firmware · huawei/s9703 firmware · huawei/s9706 firmware · huawei/s9712 firmware · huawei/s12708 firmware · huawei/s12712 firmware · huawei/5700hi firmware · huawei/5300hi firmware · +6 more
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.