CVE-2020-1828: Input Validation
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message. Attackers can send specific message to cause out-of-bound read, compromising normal service.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2020-1828?
Vulnerability CVE-2020-1828 is an input validation vulnerability in Huawei NIP6800 and Secospace USG6600 and USG9500, allowing attackers to bypass security measures.
Which software versions are affected by CVE-2020-1828?
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00, as well as Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 are affected by CVE-2020-1828.
What is the severity level of CVE-2020-1828?
CVE-2020-1828 has a severity level of 7.5 (high).
How can I fix vulnerability CVE-2020-1828?
To fix vulnerability CVE-2020-1828, it is recommended to update to the latest firmware versions provided by Huawei.
Where can I find more information about CVE-2020-1828?
You can find more information about vulnerability CVE-2020-1828 on the official Huawei Security Advisories page.