CVE-2020-1814: Race Condition
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability. An authenticated attacker may do some special operations in the affected products in some special scenarios to exploit the vulnerability. Due to improper race conditions of different operations, successful exploit will lead to Dangling pointer dereference, causing some service abnormal.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2020-1814.
What is the severity of CVE-2020-1814?
The severity of CVE-2020-1814 is medium with a CVSS score of 5.3.
Which Huawei products are affected by CVE-2020-1814?
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 are affected.
How can an attacker exploit CVE-2020-1814?
An authenticated attacker can exploit CVE-2020-1814 by performing special operations in the affected Huawei and Secospace products.
Is there a fix available for CVE-2020-1814?
Yes, Huawei has released a security advisory with recommended fixes. Please refer to the Huawei security advisory for more information.