Dangling Pointer Dereference Vulnerability in Huawei Firewalls
CVE-2020-1814
5.3MEDIUM
Key Information:
- Vendor
- Huawei
- Vendor
- CVE Published:
- 18 February 2020
Summary
Huawei NIP6800 and Secospace USG6600/USG9500 devices are impacted by a dangling pointer dereference vulnerability that could be exploited by an authenticated attacker under specific conditions. This issue arises from improper race conditions in different operations, potentially leading to service abnormalities when successfully exploited.
Affected Version(s)
NIP6800 V500R001C30
NIP6800 V500R001C60SPC500
NIP6800 V500R005C00
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved