#VU25275 Input validation error in Huawei products - CVE-2020-1828
Published: February 13, 2020
Huawei NIP6800
Huawei Secospace USG6600
USG9500
Huawei
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when the IPSec module does not validate a field in a specific message. A remote attacker can send a specially crafted message, cause out-of-bound read and compromise normal service.