CVE-2020-9087: Medium severity huawei taurus-al00a firmware vulnerability
Taurus-AL00A version 10.0.0.1(C00E1R1P1) has an out-of-bounds read vulnerability in XFRM module. An authenticated, local attacker may perform a specific operation to exploit this vulnerability. Due to insufficient validation of the parameters, which may be exploited to cause information leak.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-9087?
CVE-2020-9087 is an out-of-bounds read vulnerability in the XFRM module of the Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware.
How severe is CVE-2020-9087?
CVE-2020-9087 has a severity rating of 5.5, which is considered medium.
Which software version is affected by CVE-2020-9087?
Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware is affected by CVE-2020-9087.
How can an attacker exploit CVE-2020-9087?
An authenticated, local attacker can exploit CVE-2020-9087 by performing a specific operation that triggers an out-of-bounds read vulnerability in the XFRM module, leading to information leak.
Are all versions of Huawei Taurus-al00a affected?
No, only the Taurus-AL00A version 10.0.0.1(C00E1R1P1) firmware is affected by CVE-2020-9087.
How to mitigate the vulnerability?
To mitigate the vulnerability, Huawei recommends updating the firmware to a version that resolves the issue. Please refer to the vendor's security advisory for more information.