Use-after-free in Huawei E6878-370 - CVE-2020-1799

 

Use-after-free in Huawei E6878-370 - CVE-2020-1799

Published: May 20, 2020


Vulnerability identifier: #VU28128
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1799
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Huawei E6878-370
Software vendor:
Huawei

Description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when the software references memory after it has been freed. A remote attacker on the local network can do a series of crafted operations through web portal, cause a use-after-free condition and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Install updates from vendor's website.

External links