Multiple vulnerabilities in several Huawei Products



Published: 2020-08-27
Risk Low
Patch available YES
Number of vulnerabilities 7
CVE-ID CVE-2020-1818
CVE-2020-1819
CVE-2020-1820
CVE-2020-1821
CVE-2020-1822
CVE-2020-1823
CVE-2020-1824
CWE-ID CWE-125
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Huawei IPS Module
Server applications / IDS/IPS systems, Firewalls and proxy servers

Huawei NIP6300
Server applications / IDS/IPS systems, Firewalls and proxy servers

Huawei NIP6600
Server applications / IDS/IPS systems, Firewalls and proxy servers

Huawei NIP6800
Server applications / IDS/IPS systems, Firewalls and proxy servers

Huawei NGFW Module
Server applications / Other server solutions

Huawei Secospace USG6300
Server applications / Server solutions for antivurus protection

Huawei Secospace USG6500
Server applications / Server solutions for antivurus protection

Huawei Secospace USG6600
Server applications / Server solutions for antivurus protection

Huawei USG6000V
Server applications / Remote management servers, RDP, SSH

Vendor Huawei

Security Bulletin

This security bulletin contains information about 7 vulnerabilities.

1) Out-of-bounds read

EUVDB-ID: #VU46092

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1818

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

2) Out-of-bounds read

EUVDB-ID: #VU46093

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1819

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

3) Out-of-bounds read

EUVDB-ID: #VU46094

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1820

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

4) Out-of-bounds read

EUVDB-ID: #VU46095

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1821

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

5) Out-of-bounds read

EUVDB-ID: #VU46096

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1822

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

6) Out-of-bounds read

EUVDB-ID: #VU46097

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1823

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?

7) Out-of-bounds read

EUVDB-ID: #VU46098

Risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-1824

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the specific decoding function. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei IPS Module: V500R001C30 - V500R005C00

Huawei NGFW Module: V500R002C00 - V500R005C00

Huawei NIP6300: V500R001C30 - V500R005C00

Huawei NIP6600: V500R001C30 - V500R005C00

Huawei NIP6800: V500R001C60 - V500R005C00

Huawei Secospace USG6300: V500R001C30 - V500R005C00

Huawei Secospace USG6500: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30 - V500R005C00

Huawei USG6000V: V500R003C00


CPE2.3 External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191218-01-cops-en

Q & A

Can this vulnerability be exploited remotely?

How the attacker can exploit this vulnerability?

Is there known malware, which exploits this vulnerability?



###SIDEBAR###