First published: Wed Jan 13 2021(Updated: )
There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of bounds read when the system does the certain operation.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 5800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 5800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 6800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c20spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 7800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r019c10spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-1865.
The severity level of CVE-2020-1865 is medium with a CVSS score of 6.5.
Huawei CloudEngine 12800, 5800, and 6800 Firmware versions v200r002c50spc800, v200r003c00spc810, v200r005c00spc800, v200r005c10spc800, v200r005c20spc800, v200r019c00spc800, and v200r019c10spc800 are affected by CVE-2020-1865.
The vulnerability occurs when the software reads data past the end of the intended buffer while parsing certain PIM messages.
Yes, Huawei has released a security advisory with the recommended solution. Please refer to the official reference link for more information.