6.5

CVE-2020-9101

There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V500R005C10; NGFW Module versions V500R005C00, V500R005C10; Secospace USG6300 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6600 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; USG9500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10

Data is provided by the National Vulnerability Database (NVD)
HuaweiIps Module Firmware Versionv500r005c00
   HuaweiIps Module Version-
HuaweiIps Module Firmware Versionv500r005c10
   HuaweiIps Module Version-
HuaweiNgfw Module Firmware Versionv500r005c00
   HuaweiNgfw Module Version-
HuaweiNgfw Module Firmware Versionv500r005c10
   HuaweiNgfw Module Version-
HuaweiSecospace Usg6300 Firmware Versionv500r001c30
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r001c60
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r005c00
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6300 Firmware Versionv500r005c10
   HuaweiSecospace Usg6300 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r001c30
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r001c60
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r005c00
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6500 Firmware Versionv500r005c10
   HuaweiSecospace Usg6500 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r001c30
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r001c60
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r005c00
   HuaweiSecospace Usg6600 Version-
HuaweiSecospace Usg6600 Firmware Versionv500r005c10
   HuaweiSecospace Usg6600 Version-
HuaweiUsg9500 Firmware Versionv500r001c30
   HuaweiUsg9500 Version-
HuaweiUsg9500 Firmware Versionv500r001c60
   HuaweiUsg9500 Version-
HuaweiUsg9500 Firmware Versionv500r005c00
   HuaweiUsg9500 Version-
HuaweiUsg9500 Firmware Versionv500r005c10
   HuaweiUsg9500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.076
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.