Buffer overflow in Huawei products - CVE-2020-9067

 

Buffer overflow in Huawei products - CVE-2020-9067

Published: April 3, 2020


Vulnerability identifier: #VU26576
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9067
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and execute arbitrary code on the target system as an optical line terminal (OLT).

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

SmartAX MA5800
SmartAX EA5800
SmartAX MA5600T

How to mitigate CVE-2020-9067

Install updates from vendor's website.

SmartAX MA5800 - addressed in versions V100R018C10SPH116, V100R019C12SPH208
SmartAX EA5800 - addressed in versions V100R018C10SPH116, V100R019C10SPH208
SmartAX MA5600T - addressed in versions V800R017C10SPH229, V800R018C00SPH207, V800R018C10SPH212

External References

Related Security Bulletins