Input validation error in Huawei products - CVE-2020-1816

 

Input validation error in Huawei products - CVE-2020-1816

Published: February 19, 2020


Vulnerability identifier: #VU25432
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1816
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper processing of specific IPSEC packets. A remote attacker can send specially crafted IPSEC packets to affected devices and cause the IPSEC function of the affected device abnormal.


Affected software

Huawei Secospace USG6600
USG9500
Huawei NIP6800

How to mitigate CVE-2020-1816

Install updates from vendor's website.

Huawei Secospace USG6600 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300

External References

Related Security Bulletins