First published: Mon Oct 12 2020(Updated: )
Taurus-AL00A version 10.0.0.1(C00E1R1P1) has an out-of-bounds read vulnerability in XFRM module. An authenticated, local attacker may perform a specific operation to exploit this vulnerability. Due to insufficient validation of the parameters, which may be exploited to cause information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus-al00a Firmware | =10.0.0.1\(c00e1r1p1\) | |
Huawei Taurus-al00a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9087 is an out-of-bounds read vulnerability in the XFRM module of the Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware.
CVE-2020-9087 has a severity rating of 5.5, which is considered medium.
Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware is affected by CVE-2020-9087.
An authenticated, local attacker can exploit CVE-2020-9087 by performing a specific operation that triggers an out-of-bounds read vulnerability in the XFRM module, leading to information leak.
No, only the Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware is affected by CVE-2020-9087.
To mitigate the vulnerability, Huawei recommends updating the firmware to a version that resolves the issue. Please refer to the vendor's security advisory for more information.