Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200715-01-OPENSSL
HistoryJul 15, 2020 - 12:00 a.m.

Security Advisory - Denial of Service Vulnerability in OpenSSL

2020-07-1500:00:00
Huawei Technologies
www.huawei.com
45
openssl
dos vulnerability
tls 1.3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.081

Percentile

94.3%

There is a Denial of Service (DoS) vulnerability in Openssl. Specific function in Openssl may crash during or after the TLS 1.3 handshake due to a NULL pointer dereference. Attacker may send crafted request packet to the target host service to exploit this vulnerability. Successful exploit may cause the affected service crash or deny of service. (Vulnerability ID: HWPSIRT-2020-16617)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-1967.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200715-01-openssl-en

Affected configurations

Vulners
Node
huaweifusioncube_firmwareMatch3.2.1.spc201
OR
huaweifusioncube_firmwareMatch6.0.0
OR
huaweifusioncube_firmwareMatch6.0.rc3
OR
huaweimyna_firmwareMatch9.0.1.10
OR
huaweielog_firmwareMatchv200r007c10spc102
VendorProductVersionCPE
huaweifusioncube_firmware3.2.1.spc201cpe:2.3:o:huawei:fusioncube_firmware:3.2.1.spc201:*:*:*:*:*:*:*
huaweifusioncube_firmware6.0.0cpe:2.3:o:huawei:fusioncube_firmware:6.0.0:*:*:*:*:*:*:*
huaweifusioncube_firmware6.0.rc3cpe:2.3:o:huawei:fusioncube_firmware:6.0.rc3:*:*:*:*:*:*:*
huaweimyna_firmware9.0.1.10cpe:2.3:o:huawei:myna_firmware:9.0.1.10:*:*:*:*:*:*:*
huaweielog_firmwarev200r007c10spc102cpe:2.3:o:huawei:elog_firmware:v200r007c10spc102:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.081

Percentile

94.3%