CVE-2020-9071
—CVSS 3.1
6.5 medium
EPSS
<1%p48
Published
()
Modified
Description
There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00
- Vendors
- huawei
- Products
- ar120-s firmware, ar1200 firmware, ar1200-s firmware, ar150 firmware, ar150-s firmware, ar160 firmware, ar200 firmware, ar200-s firmware, ar2200 firmware, ar2200-s firmware, ar3200 firmware, ar3600 firmware
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.