#VU25432 Input validation error in Huawei products - CVE-2020-1816


Vulnerability identifier: #VU25432

Vulnerability risk: Medium

CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-1816

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Huawei NIP6800
Server applications / IDS/IPS systems, Firewalls and proxy servers
Huawei Secospace USG6600
Server applications / Server solutions for antivurus protection
USG9500
Hardware solutions / Routers & switches, VoIP, GSM, etc

Vendor: Huawei

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper processing of specific IPSEC packets. A remote attacker can send specially crafted IPSEC packets to affected devices and cause the IPSEC function of the affected device abnormal.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Huawei NIP6800: V500R001C30 - V500R005C00

Huawei Secospace USG6600: V500R001C30SPC200 - V500R001C60SPC500

USG9500: V500R001C30SPC200 - V500R005C00


External links
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200212-03-firewall-en


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability