CVE-2020-1865: Medium severity huawei cloudengine 12800 vulnerability
There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of bounds read when the system does the certain operation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this out-of-bounds read vulnerability in Huawei CloudEngine products?
The vulnerability ID is CVE-2020-1865.
What is the severity level of CVE-2020-1865?
The severity level of CVE-2020-1865 is medium with a CVSS score of 6.5.
Which Huawei CloudEngine products are affected by CVE-2020-1865?
Huawei CloudEngine 12800, 5800, and 6800 Firmware versions v200r002c50spc800, v200r003c00spc810, v200r005c00spc800, v200r005c10spc800, v200r005c20spc800, v200r019c00spc800, and v200r019c10spc800 are affected by CVE-2020-1865.
How does the vulnerability CVE-2020-1865 occur?
The vulnerability occurs when the software reads data past the end of the intended buffer while parsing certain PIM messages.
Is there a fix available for CVE-2020-1865?
Yes, Huawei has released a security advisory with the recommended solution. Please refer to the official reference link for more information.