Input validation error in Huawei products - CVE-2020-1814
Published: February 13, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing specific IPSEC packets. A remote attacker can send a specially crafted IPSEC packet to affected devices and cause the IPSEC function of the affected device abnormal.
Affected software
USG9500
Huawei NIP6800
How to mitigate CVE-2020-1814
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300