Out-of-bounds read in Huawei products - CVE-2020-1866

 

Out-of-bounds read in Huawei products - CVE-2020-1866

Published: January 4, 2021


Vulnerability identifier: #VU49225
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1866
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when parsing certain crafted DHCP messages. A remote attacker on the local network can trigger out-of-bounds read error and cause a denial of service condition on the target system.


Affected software

Huawei S12700
Huawei S5700
Huawei S2700
Huawei S6700
Huawei S7700
Huawei S9700
USG9500
Huawei Secospace USG6600
Huawei NIP6800

How to mitigate CVE-2020-1866

Install updates from vendor's website.

Huawei S12700 - update to V200R013C00SPC500
Huawei S2700 - update to V200R013C00SPC500
Huawei S5700 - update to V200R013C00SPC500
Huawei S6700 - update to V200R013C00SPC500
Huawei S7700 - update to V200R013C00SPC500
Huawei S9700 - update to V200R013C00SPC500
Huawei Secospace USG6600 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6800 - update to V500R005C20SPC300

External References

Related Security Bulletins