Out-of-Bounds Write Vulnerability in Huawei Secospace Products
CVE-2020-1876

7.5HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
28 February 2020

Summary

The Secospace USG6600 and USG9500 series from Huawei are susceptible to an out-of-bounds write vulnerability that allows unauthenticated attackers to exploit the system. By sending specially crafted malformed packets to the devices, which lack sufficient validation, an attacker could trigger an unexpected reboot of the affected processes, leading to potential service disruption. Users are advised to review their device configurations and apply any available security updates to mitigate this risk.

Affected Version(s)

NIP6800;Secospace USG6600;USG9500 V500R001C30,V500R001C60SPC500,V500R005C00

NIP6800;Secospace USG6600;USG9500 V500R001C30SPC600,V500R001C60SPC500,V500R005C00

NIP6800;Secospace USG6600;USG9500 V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.