First published: Mon Oct 12 2020(Updated: )
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a buffer overflow vulnerability. A function in a module does not verify inputs sufficiently. Attackers can exploit this vulnerability by sending specific request. This could compromise normal service of the affected device.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus ncmdump | <10.1.0.156 | |
Huawei Taurus ncmdump |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9238 is classified as a buffer overflow vulnerability which can significantly impact device security.
To mitigate CVE-2020-9238, upgrade the Taurus-AN00B firmware to version 10.1.0.156 or later.
An attacker can exploit CVE-2020-9238 by sending specially crafted requests to the affected device, potentially compromising its normal function.
CVE-2020-9238 affects Huawei Taurus-AN00B devices running firmware versions earlier than 10.1.0.156.
The impact and exploitability of CVE-2020-9238 depend on the deployment of affected Huawei devices in various environments.