First published: Fri Dec 27 2024(Updated: )
There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal. (Vulnerability ID: HWPSIRT-2017-10105) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9085.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Huawei B612 | =b612s-25dtcpu-v100r001b192d03sp00c234 | |
Huawei B612 | =b612s-25dtcpu-v100r001b192d03sp00c287 | |
Huawei B612 | =b612s-25dtcpu-v100r001b192d05sp00c00 | |
Huawei B612 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-9085 is classified as medium due to the potential for process abnormality caused by a NULL pointer dereference.
To fix CVE-2020-9085, it is recommended to update affected Huawei products to the latest firmware version available from Huawei.
CVE-2020-9085 affects specific versions of the Huawei B612 firmware, including versions b612s-25dtcpu-v100r001b192d03sp00c234, b612s-25dtcpu-v100r001b192d03sp00c287, and b612s-25dtcpu-v100r001b192d05sp00c00.
Yes, CVE-2020-9085 can potentially be exploited remotely through specially crafted POST messages sent to the vulnerable devices.
Successful exploitation of CVE-2020-9085 could lead to abnormal behavior in processes of the affected Huawei products.