First published: Wed Jan 13 2021(Updated: )
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Nip6800 Firmware | =v500r001c30 | |
Huawei Nip6800 Firmware | =v500r001c60spc500 | |
Huawei Nip6800 Firmware | =v500r005c00 | |
Huawei NIP6800 | ||
Huawei S12700 Firmware | =v200r008c00 | |
Huawei S12700 | ||
Huawei S2700 Firmware | =v200r008c00 | |
Huawei S2700 | ||
Huawei S5700 Firmware | =v200r008c00 | |
Huawei S5700 | ||
Huawei S6700 Firmware | =v200r008c00 | |
Huawei S6700 | ||
Huawei S7700 Firmware | =v200r008c00 | |
Huawei S7700 | ||
Huawei S9700 Firmware | =v200r008c00 | |
Huawei S9700 | ||
Huawei Secospace Usg6600 Firmware | =v500r001c30spc200 | |
Huawei Secospace Usg6600 Firmware | =v500r001c30spc600 | |
Huawei Secospace Usg6600 Firmware | =v500r001c60spc500 | |
Huawei Secospace Usg6600 Firmware | =v500r005c00 | |
Huawei Secospace USG6600 | ||
Huawei Usg9500 Firmware | =v500r001c30spc300 | |
Huawei Usg9500 Firmware | =v500r001c30spc600 | |
Huawei Usg9500 Firmware | =v500r001c60spc500 | |
Huawei Usg9500 Firmware | =v500r005c00 | |
Huawei USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-1866.
The severity of CVE-2020-1866 is medium (6.5).
The affected products include Huawei NIP6800 Firmware versions V500R001C30, V500R001C60SPC500, and V500R005C00.
Successful exploitation of CVE-2020-1866 could cause certain service abnormalities.
More information about CVE-2020-1866 can be found at the following link: [Huawei Security Advisory](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-09-eudemon-en).