Double Free in Huawei products - CVE-2020-1829
Published: February 12, 2020
Vulnerability identifier: #VU25272
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1829
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise normal service.
The vulnerability exists due to a boundary error when the IPSec module handles a message improperly. A remote attacker can send specific message to affected product, trigger double free error and compromise normal service.
Affected software
Huawei Secospace USG6600
USG9500
Huawei NIP6800
USG9500
Huawei NIP6800
How to mitigate CVE-2020-1829
Install updates from vendor's website.
Huawei Secospace USG6600 - update to V500R005C00SPC200
USG9500 - update to V500R005C00SPC200
Huawei NIP6800 - update to V500R005C00SPC200
USG9500 - update to V500R005C00SPC200
Huawei NIP6800 - update to V500R005C00SPC200