Input validation error in Huawei products - CVE-2020-1816
Published: February 19, 2020
Vulnerability identifier: #VU25432
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1816
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper processing of specific IPSEC packets. A remote attacker can send specially crafted IPSEC packets to affected devices and cause the IPSEC function of the affected device abnormal.
Affected software
Huawei Secospace USG6600
USG9500
Huawei NIP6800
USG9500
Huawei NIP6800
How to mitigate CVE-2020-1816
Install updates from vendor's website.
Huawei Secospace USG6600 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300