First published: Fri May 29 2020(Updated: )
There is a denial of service vulnerability in some Huawei products. Due to improper memory management, memory leakage may occur in some special cases. Attackers can perform a series of operations to exploit this vulnerability. Successful exploit may cause a denial of service. Affected product versions include: CloudEngine 12800 versions V200R019C00SPC800; CloudEngine 5800 versions V200R019C00SPC800; CloudEngine 6800 versions V200R005C20SPC800, V200R019C00SPC800; CloudEngine 7800 versions V200R019C00SPC800; NE40E versions V800R011C00SPC200, V800R011C00SPC300, V800R011C10SPC100; NE40E-F versions V800R011C00SPC200, V800R011C10SPC100; NE40E-M versions V800R011C00SPC200, V800R011C10SPC100.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r019c00 | |
Huawei Cloudengine 12800 Firmware | =v200r019c00spc600 | |
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c10 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 6800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1870 is a denial of service vulnerability in some Huawei products due to improper memory management.
Attackers can exploit CVE-2020-1870 by performing a series of operations that cause memory leakage and may result in a denial of service.
Huawei Cloudengine 12800 Firmware versions v200r019c00, v200r019c00spc600, v200r019c00spc800, and v200r019c10 are affected by CVE-2020-1870.
CVE-2020-1870 has a severity score of 7.5 (high).
Huawei has released a security advisory with mitigation measures for CVE-2020-1870. Please refer to the official Huawei advisory for details.