First published: Tue Dec 29 2020(Updated: )
There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with specific message properly. Attackers can exploit this vulnerability by sending malicious packet. This can lead to denial of service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 5800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r005c20spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9094 is an out of bound read vulnerability in some versions of Huawei CloudEngine product.
Attackers can exploit this vulnerability by sending a malicious packet, which can lead to a denial of service.
Huawei CloudEngine versions v200r019c00spc800, v200r005c20spc800, and v200r019c00spc800 are affected by CVE-2020-9094.
CVE-2020-9094 has a severity rating of 7.5, which is considered high.
To fix CVE-2020-9094, it is recommended to apply the necessary security patches provided by Huawei.