First published: Thu Mar 12 2020(Updated: )
Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vulnerability. Due to a logical flaw in a JSON parsing routine, a remote, unauthenticated attacker could exploit this vulnerability to disrupt service in the affected products.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Usg6000v Firmware | =v500r001c20spc300 | |
Huawei Usg6000v Firmware | =v500r003c00spc100 | |
Huawei Usg6000v Firmware | =v500r005c00spc100 | |
Huawei USG6000V |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-1863.
The severity of CVE-2020-1863 is high with a severity value of 7.5.
Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 are affected by CVE-2020-1863.
A remote, unauthenticated attacker can exploit the vulnerability by taking advantage of a logical flaw in a JSON parsing routine.
Refer to the Huawei security advisory for information on the fix for CVE-2020-1863.