Lucene search

K
nvd[email protected]NVD:CVE-2020-1866
HistoryJan 13, 2021 - 11:15 p.m.

CVE-2020-1866

2021-01-1323:15:13
CWE-125
web.nvd.nist.gov
5
out-of-bounds read vulnerability
multiple product versions
crafted dhcp messages
service abnormal

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

25.7%

There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.

Affected configurations

Nvd
Node
huaweinip6800_firmwareMatchv500r001c30
OR
huaweinip6800_firmwareMatchv500r001c60spc500
OR
huaweinip6800_firmwareMatchv500r005c00
AND
huaweinip6800Match-
Node
huaweis12700_firmwareMatchv200r008c00
AND
huaweis12700Match-
Node
huaweis2700_firmwareMatchv200r008c00
AND
huaweis2700Match-
Node
huaweis5700_firmwareMatchv200r008c00
AND
huaweis5700Match-
Node
huaweis6700_firmwareMatchv200r008c00
AND
huaweis6700Match-
Node
huaweis7700_firmwareMatchv200r008c00
AND
huaweis7700Match-
Node
huaweis9700_firmwareMatchv200r008c00
AND
huaweis9700Match-
Node
huaweisecospace_usg6600_firmwareMatchv500r001c30spc200
OR
huaweisecospace_usg6600_firmwareMatchv500r001c30spc600
OR
huaweisecospace_usg6600_firmwareMatchv500r001c60spc500
OR
huaweisecospace_usg6600_firmwareMatchv500r005c00
AND
huaweisecospace_usg6600Match-
Node
huaweiusg9500_firmwareMatchv500r001c30spc300
OR
huaweiusg9500_firmwareMatchv500r001c30spc600
OR
huaweiusg9500_firmwareMatchv500r001c60spc500
OR
huaweiusg9500_firmwareMatchv500r005c00
AND
huaweiusg9500Match-
VendorProductVersionCPE
huaweinip6800_firmwarev500r001c30cpe:2.3:o:huawei:nip6800_firmware:v500r001c30:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r001c60spc500cpe:2.3:o:huawei:nip6800_firmware:v500r001c60spc500:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r005c00cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:*
huaweinip6800-cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:*
huaweis12700_firmwarev200r008c00cpe:2.3:o:huawei:s12700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis12700-cpe:2.3:h:huawei:s12700:-:*:*:*:*:*:*:*
huaweis2700_firmwarev200r008c00cpe:2.3:o:huawei:s2700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis2700-cpe:2.3:h:huawei:s2700:-:*:*:*:*:*:*:*
huaweis5700_firmwarev200r008c00cpe:2.3:o:huawei:s5700_firmware:v200r008c00:*:*:*:*:*:*:*
huaweis5700-cpe:2.3:h:huawei:s5700:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 261

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

6.5

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

25.7%

Related for NVD:CVE-2020-1866