CVE-2020-9093: Use After Free
Published Dec 29, 2020
·Updated
There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which makes a function refer to memory after it has been freed. Attackers can exploit this vulnerability by running a crafted application with common privilege. This would compromise normal service.
Affected Software
2 affected components
Huawei Taurus-al00a Firmware=10.0.0.1\(c00e1r1p1\)
Huawei Taurus-AL00A
Event History
Dec 29, 2020
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-9093.
2
What is the severity of CVE-2020-9093?
The severity of CVE-2020-9093 is medium, with a severity value of 5.5.
3
Which software versions are affected by CVE-2020-9093?
Taurus-AL00A versions 10.0.0.1(C00E1R1P1) of Huawei Taurus-al00a Firmware are affected by CVE-2020-9093.
4
How can attackers exploit CVE-2020-9093?
Attackers can exploit CVE-2020-9093 by running a crafted application with common privileges.
5
Is there a fix available for CVE-2020-9093?
Please refer to the advisory provided by Huawei for information on fixes for CVE-2020-9093.