First published: Mon Oct 12 2020(Updated: )
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out-of-bounds read and write vulnerability. Some functions do not verify inputs sufficiently. Attackers can exploit this vulnerability by sending specific request. This could compromise normal service of the affected device.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus ncmdump | =10.1.0.156\(c00e155r7p2\) | |
Huawei Taurus ncmdump |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9091 is classified as a high severity vulnerability due to its potential to allow attackers to compromise the affected device's normal service.
To fix CVE-2020-9091, users should update their Huawei Taurus-AN00B firmware to version 10.1.0.156(C00E155R7P2) or later.
CVE-2020-9091 affects Huawei Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2).
Exploitation of CVE-2020-9091 could lead to an out-of-bounds read and write, potentially compromising the normal functionality of the damaged device.
Attackers can exploit CVE-2020-9091 by sending specifically crafted requests that take advantage of insufficient input verification.