Buffer overflow in Huawei products - CVE-2020-9067
Published: April 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and execute arbitrary code on the target system as an optical line terminal (OLT).
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SmartAX EA5800
SmartAX MA5600T
How to mitigate CVE-2020-9067
SmartAX EA5800 - addressed in versions V100R018C10SPH116, V100R019C10SPH208
SmartAX MA5600T - addressed in versions V800R017C10SPH229, V800R018C00SPH207, V800R018C10SPH212