6.5
CVE-2020-1866
- EPSS 0.04%
- Published 13.01.2021 23:15:13
- Last modified 21.11.2024 05:11:30
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Nip6800 Firmware Versionv500r001c30
Huawei ≫ Nip6800 Firmware Versionv500r001c60spc500
Huawei ≫ Nip6800 Firmware Versionv500r005c00
Huawei ≫ S12700 Firmware Versionv200r008c00
Huawei ≫ S2700 Firmware Versionv200r008c00
Huawei ≫ S5700 Firmware Versionv200r008c00
Huawei ≫ S6700 Firmware Versionv200r008c00
Huawei ≫ S7700 Firmware Versionv200r008c00
Huawei ≫ S9700 Firmware Versionv200r008c00
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c30spc200
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c30spc600
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c60spc500
Huawei ≫ Secospace Usg6600 Firmware Versionv500r005c00
Huawei ≫ Usg9500 Firmware Versionv500r001c30spc300
Huawei ≫ Usg9500 Firmware Versionv500r001c30spc600
Huawei ≫ Usg9500 Firmware Versionv500r001c60spc500
Huawei ≫ Usg9500 Firmware Versionv500r005c00
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.091 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:N/I:N/A:P
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.