First published: Fri Sep 18 2020(Updated: )
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus ncmdump | <10.1.0.156\(c00e155r7p2\) | |
Huawei Taurus ncmdump |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9084 is classified as a high severity use-after-free vulnerability that could lead to privilege escalation.
To fix CVE-2020-9084, update the Huawei Taurus-AN00B firmware to version 10.1.0.156 or later.
CVE-2020-9084 can be exploited by an authenticated, local attacker performing specific operations.
Successful exploitation of CVE-2020-9084 may allow the attacker to obtain higher privileges and compromise the service.
CVE-2020-9084 affects all versions of Huawei Taurus-AN00B firmware prior to 10.1.0.156.