CVE-2020-1863: High severity Huawei Usg6000v Firmware vulnerability
Published Mar 12, 2020
·Updated
Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vulnerability. Due to a logical flaw in a JSON parsing routine, a remote, unauthenticated attacker could exploit this vulnerability to disrupt service in the affected products.
Affected Software
8 affected components
Huawei Usg6000v Firmware=v500r001c20spc300
Huawei Usg6000v Firmware=v500r003c00spc100
Huawei Usg6000v Firmware=v500r005c00spc100
Huawei USG6000V
All of the following
Any of the following
Huawei Usg6000v Firmware=v500r001c20spc300
Huawei Usg6000v Firmware=v500r003c00spc100
Huawei Usg6000v Firmware=v500r005c00spc100
Huawei USG6000V
Event History
Mar 12, 2020
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-1863.
2
What is the severity of CVE-2020-1863?
The severity of CVE-2020-1863 is high with a severity value of 7.5.
3
Which products are affected by CVE-2020-1863?
Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 are affected by CVE-2020-1863.
4
How can the vulnerability be exploited?
A remote, unauthenticated attacker can exploit the vulnerability by taking advantage of a logical flaw in a JSON parsing routine.
5
Is there a fix for CVE-2020-1863?
Refer to the Huawei security advisory for information on the fix for CVE-2020-1863.