5.3

CVE-2020-1821

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)

The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.

Data is provided by the National Vulnerability Database (NVD)
HuaweiIps Module Firmware Versionv500r001c30
   HuaweiIps Module Version-
HuaweiIps Module Firmware Versionv500r001c60
   HuaweiIps Module Version-
HuaweiIps Module Firmware Versionv500r005c00
   HuaweiIps Module Version-
HuaweiNgfw Module Firmware Versionv500r002c00
   HuaweiNgfw Module Version-
HuaweiNgfw Module Firmware Versionv500r002c20
   HuaweiNgfw Module Version-
HuaweiNgfw Module Firmware Versionv500r005c00
   HuaweiNgfw Module Version-
HuaweiNip6300 Firmware Versionv500r001c30
   HuaweiNip6300 Version-
HuaweiNip6300 Firmware Versionv500r001c60
   HuaweiNip6300 Version-
HuaweiNip6300 Firmware Versionv500r005c00
   HuaweiNip6300 Version-
HuaweiNip6600 Firmware Versionv500r001c30
   HuaweiNip6600 Version-
HuaweiNip6600 Firmware Versionv500r001c60
   HuaweiNip6600 Version-
HuaweiNip6600 Firmware Versionv500r005c00
   HuaweiNip6600 Version-
HuaweiNip6800 Firmware Versionv500r001c60
   HuaweiNip6800 Version-
HuaweiNip6800 Firmware Versionv500r005c00
   HuaweiNip6800 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r001c30
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r001c60
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r005c00
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r001c30
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r001c60
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r005c00
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r001c30
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r005c00
   HuaweiSecospace Usg6600 Version-
HuaweiUsg6000v Firmware Versionv500r003c00
   HuaweiUsg6000v Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.234
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
psirt@huawei.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.