CVE-2020-1829: Double Free
Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Attackers can send specific message to cause double free memory. This may compromise normal service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-1829.
Which Huawei products are affected by this vulnerability?
Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 are affected by this vulnerability.
What is the severity rating of CVE-2020-1829?
The severity rating of CVE-2020-1829 is high with a score of 7.5.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by sending a specific message to cause double free memory.
Is there a fix available for this vulnerability?
To fix this vulnerability, it is recommended to follow the mitigation steps provided in the vendor's security advisory.