ZeroHour

CVE-2020-9071

CVSS 3.1
6.5 medium
EPSS
<1%p48
Published
()
Modified
Description

There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00

Vendors
huawei
Products
ar120-s firmware, ar1200 firmware, ar1200-s firmware, ar150 firmware, ar150-s firmware, ar160 firmware, ar200 firmware, ar200-s firmware, ar2200 firmware, ar2200-s firmware, ar3200 firmware, ar3600 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.