Out-of-bounds read in Huawei products - CVE-2020-1865
Published: January 4, 2021
Vulnerability identifier: #VU49226
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1865
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition. A remote attacker on the local network can trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
Huawei CloudEngine 12800
Huawei CloudEngine 7800
Huawei CloudEngine 6800
Huawei CloudEngine 5800
Huawei CloudEngine 7800
Huawei CloudEngine 6800
Huawei CloudEngine 5800
How to mitigate CVE-2020-1865
Install updates from vendor's website.
Huawei CloudEngine 12800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 7800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 6800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 5800 - addressed in versions V200R005C10SPC800+V200R005SPH025, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 7800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 6800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 5800 - addressed in versions V200R005C10SPC800+V200R005SPH025, V200R019C10SPC800+V200R019SPH006