CVE-2020-9101
Published: Jul 17, 2020
Modified: Aug 4, 2024
Description
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V500R005C10; NGFW Module versions V500R005C00, V500R005C10; Secospace USG6300 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6600 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; USG9500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10
| Vendor | Product | Versions |
|---|---|---|
Huawei | IPS Module | affected V500R005C00affected V500R005C10 |
Huawei | NGFW Module | affected V500R005C00affected V500R005C10 |
Huawei | Secospace USG6300 | affected V500R001C30affected V500R001C60affected V500R005C00affected V500R005C10 |
Huawei | Secospace USG6500 | affected V500R001C30affected V500R001C60affected V500R005C00affected V500R005C10 |
Huawei | Secospace USG6600 | affected V500R001C30affected V500R001C60affected V500R005C00affected V500R005C10 |
Huawei | USG9500 | affected V500R001C30affected V500R001C60affected V500R005C00affected V500R005C10 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now