Input validation error in Huawei products - CVE-2020-1828
Published: February 13, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when the IPSec module does not validate a field in a specific message. A remote attacker can send a specially crafted message, cause out-of-bound read and compromise normal service.
Affected software
USG9500
Huawei NIP6800
How to mitigate CVE-2020-1828
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300