First published: Fri Feb 28 2020(Updated: )
NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write vulnerability. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Nip6800 Firmware | =v500r001c30 | |
Huawei Nip6800 Firmware | =v500r001c60spc500 | |
Huawei Nip6800 Firmware | =v500r005c00 | |
Huawei NIP6800 | ||
Huawei Secospace Usg6600 Firmware | =v500r001c30spc600 | |
Huawei Secospace Usg6600 Firmware | =v500r001c60spc500 | |
Huawei Secospace Usg6600 Firmware | =v500r005c00 | |
Huawei Secospace USG6600 | ||
Huawei Usg9500 Firmware | =v500r001c30spc200 | |
Huawei Usg9500 Firmware | =v500r001c30spc600 | |
Huawei Usg9500 Firmware | =v500r001c60spc500 | |
Huawei Usg9500 Firmware | =v500r005c00 | |
Huawei USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security advisory is CVE-2020-1876.
NIP6800, Secospace USG6600, and USG9500 with versions of V500R001C30, V500R001C60SPC500, and V500R005C00SPC100 are affected by this vulnerability.
An unauthenticated attacker can exploit this vulnerability by crafting malformed packets with specific parameter and sending them to the affected products.
The severity of CVE-2020-1876 is high with a CVSS score of 7.5.
To fix this vulnerability, it is recommended to apply the patches and upgrades provided by Huawei.