Out-of-bounds read in Huawei products - CVE-2020-9094
Published: December 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when a module does not deal with specific message properly. A remote attacker can send a malicious packet, trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
Huawei CloudEngine 5800
Huawei CloudEngine 7800
Huawei CloudEngine 12800
How to mitigate CVE-2020-9094
Huawei CloudEngine 12800 - update to V200R019C10SPC800
Huawei CloudEngine 5800 - update to V200R019C10SPC800
Huawei CloudEngine 7800 - update to V200R019C10SPC800