6.1

CVE-2020-36602

There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause out-of-bounds read and write.

Data is provided by the National Vulnerability Database (NVD)
Huawei577hota-cm-h-shark-bd Firmware Version1.0.0.577
   Huawei577hota-cm-h-shark-bd Version-
Huawei586-hota-cm-h-shark-bd Firmware Version1.0.0.586
   Huawei586-hota-cm-h-shark-bd Version-
Huawei588-hota-cm-h-shark-bd Firmware Version1.0.0.588
   Huawei588-hota-cm-h-shark-bd Version-
Huawei606-hota-cm-h-shark-bd Firmware Version1.0.0.606
   Huawei606-hota-cm-h-shark-bd Version-
HuaweiBi-acc-report Firmware Version1.0.0.1
   HuaweiBi-acc-report Version-
HuaweiBi-acc-report Firmware Version1.0.0.2
   HuaweiBi-acc-report Version-
HuaweiBi-acc-report Firmware Version1.0.0.3
   HuaweiBi-acc-report Version-
HuaweiBi-acc-report Firmware Version1.0.0.4
   HuaweiBi-acc-report Version-
HuaweiBi-acc-report Firmware Version1.0.0.5
   HuaweiBi-acc-report Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.106
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.116
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.202
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.208
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.216
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.226
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.228
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.510
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.520
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.522
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.566
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.576
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.578
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.586
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.0.0.588
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.208
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.216
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.226
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.228
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.510
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.520
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.522
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.566
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.578
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.586
   HuaweiCm-h-shark-bd Version-
HuaweiCm-h-shark-bd Firmware Version1.9.0.588
   HuaweiCm-h-shark-bd Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.234
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.1 0.9 5.2
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.