Resource management error in Huawei products - CVE-2020-1881

 

Resource management error in Huawei products - CVE-2020-1881

Published: February 19, 2020 / Updated: April 30, 2020


Vulnerability identifier: #VU25434
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1881
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper resource management of the function. A remote attacker on the local network can perform specific operations to trigger the function of the affected device and cause service abnormal on affected devices.


Affected software

Huawei Secospace USG6600
USG9500
Huawei NIP6800
OceanStor 5310 V5

How to mitigate CVE-2020-1881

Install updates from vendor's website.

Huawei Secospace USG6600 - update to V500R005C00SPC200
USG9500 - update to V500R005C00SPC200
Huawei NIP6800 - update to V500R005C00SPC200
OceanStor 5310 V5 - update to V500R007C60SPC300

External References

Related Security Bulletins