Lucene search

K
cveHuaweiCVE-2020-1866
HistoryJan 13, 2021 - 11:15 p.m.

CVE-2020-1866

2021-01-1323:15:13
CWE-125
huawei
web.nvd.nist.gov
33
cve-2020-1866
security
vulnerability
out-of-bounds read
dhcp
nip6800
s12700
s2700
s5700
s6700
s7700
s9700
secospace usg6600
usg9500
nvd

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

25.7%

There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.

Affected configurations

Nvd
Vulners
Node
huaweinip6800_firmwareMatchv500r001c30
OR
huaweinip6800_firmwareMatchv500r001c60spc500
OR
huaweinip6800_firmwareMatchv500r005c00
AND
huaweinip6800Match-
Node
huaweis12700_firmwareMatchv200r008c00
AND
huaweis12700Match-
Node
huaweis2700_firmwareMatchv200r008c00
AND
huaweis2700Match-
Node
huaweis5700_firmwareMatchv200r008c00
AND
huaweis5700Match-
Node
huaweis6700_firmwareMatchv200r008c00
AND
huaweis6700Match-
Node
huaweis7700_firmwareMatchv200r008c00
AND
huaweis7700Match-
Node
huaweis9700_firmwareMatchv200r008c00
AND
huaweis9700Match-
Node
huaweisecospace_usg6600_firmwareMatchv500r001c30spc200
OR
huaweisecospace_usg6600_firmwareMatchv500r001c30spc600
OR
huaweisecospace_usg6600_firmwareMatchv500r001c60spc500
OR
huaweisecospace_usg6600_firmwareMatchv500r005c00
AND
huaweisecospace_usg6600Match-
Node
huaweiusg9500_firmwareMatchv500r001c30spc300
OR
huaweiusg9500_firmwareMatchv500r001c30spc600
OR
huaweiusg9500_firmwareMatchv500r001c60spc500
OR
huaweiusg9500_firmwareMatchv500r005c00
AND
huaweiusg9500Match-
VendorProductVersionCPE
huaweinip6800_firmwarev500r001c30cpe:2.3:o:huawei:nip6800_firmware:v500r001c30:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r001c60spc500cpe:2.3:o:huawei:nip6800_firmware:v500r001c60spc500:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r005c00cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:*
huaweinip6800-cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:*
huaweis12700_firmwarev200r008c00cpe:2.3:o:huawei:s12700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis12700-cpe:2.3:h:huawei:s12700:-:*:*:*:*:*:*:*
huaweis2700_firmwarev200r008c00cpe:2.3:o:huawei:s2700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis2700-cpe:2.3:h:huawei:s2700:-:*:*:*:*:*:*:*
huaweis5700_firmwarev200r008c00cpe:2.3:o:huawei:s5700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis5700-cpe:2.3:h:huawei:s5700:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CNA Affected

[
  {
    "product": "NIP6800;S12700;S2700;S5700;S6700;S7700;S9700;Secospace USG6600;USG9500",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "V500R001C30,V500R001C60SPC500,V500R005C00"
      },
      {
        "status": "affected",
        "version": "V200R008C00"
      },
      {
        "status": "affected",
        "version": "V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00"
      },
      {
        "status": "affected",
        "version": "V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00"
      }
    ]
  }
]

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

25.7%

Related for CVE-2020-1866