Dangling Pointer Dereference Vulnerability in Huawei Firewalls
CVE-2020-1814

5.3MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
18 February 2020

Summary

Huawei NIP6800 and Secospace USG6600/USG9500 devices are impacted by a dangling pointer dereference vulnerability that could be exploited by an authenticated attacker under specific conditions. This issue arises from improper race conditions in different operations, potentially leading to service abnormalities when successfully exploited.

Affected Version(s)

NIP6800 V500R001C30

NIP6800 V500R001C60SPC500

NIP6800 V500R005C00

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.