Out-of-Bounds Read Vulnerability in Huawei CloudEngine Products
CVE-2020-1865

6.5MEDIUM

Key Information:

Summary

An out-of-bounds read vulnerability exists in Huawei CloudEngine products due to improper handling of PIM messages. When the software processes these messages, it can read data beyond the intended buffer limit, potentially allowing an adjacent attacker to exploit the flaw by sending specially crafted PIM messages. If successfully executed, this exploit could lead to unauthorized data access or system instability during specific operations.

Affected Version(s)

CloudEngine 12800;CloudEngine 5800;CloudEngine 6800;CloudEngine 7800 V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800

CloudEngine 12800;CloudEngine 5800;CloudEngine 6800;CloudEngine 7800 V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800,V200R019C10SPC800

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.