Junglewise Threat Intelligence

CVE-2016-5822: Huawei OceanStor 5800 denial of service via crafted HTTP packets

CVE-2016-5822 · Severity: high · CVSS 7.5 · Published 2017-01-27

Vendors: Huawei.

Executive brief

Huawei OceanStor 5800 storage systems are susceptible to a denial-of-service vulnerability. An attacker can send a flood of specially crafted web traffic to the device, causing its processor to become overloaded. This results in the storage system becoming unresponsive, potentially disrupting data access and business operations.

Technical details

A resource management error (CWE-399) in the HTTP service of Huawei OceanStor 5800 V3 devices allows unauthenticated remote attackers to trigger a denial-of-service condition. The vulnerability is exploited by sending a large volume of abnormal HTTP packets containing incorrectly coded fields. This causes the device's CPU usage to spike to critical levels, rendering the management interface or the device itself unresponsive. The issue is resolved in version V300R002C10SPC100.

Affected products

  • Huawei OceanStor 5800 V3 Versions before V300R002C10SPC100

Timeline

  • 2016-06-22: disclosed: Initial advisory released by Huawei
  • 2016-07-06: patched: Updated advisory with fixed version and CVE ID
  • 2017-01-27: advisory: NVD publication date

References