Security Advisory: Integer Overflow Vulnerability in Some Huawei Products SA No: huawei-sa-20170816-01-nas Initial Release Date: 2017-08-16 Last Release Date: 2017-08-16 Summary: - Integer overflow vulnerability affecting certain Huawei products. An attacker can exploit this by sending a response message with an illegal length field, causing an integer overflow and potentially restarting the modem system. - Vulnerability ID: HWPSIRT-2017-06005 - CVE ID: CVE-2017-2717 - Huawei has released software updates to address this issue. Additional Information Links: - Software Versions and Fixes - Impact - Vulnerability Scoring Details - Technique Details - Temporary Fix - Obtaining Fixed Software - Source - Revision History - FAQs - Huawei Security Procedures - Declaration