#VU26576 Buffer overflow in Huawei products - CVE-2020-9067

 

#VU26576 Buffer overflow in Huawei products - CVE-2020-9067

Published: April 3, 2020


Vulnerability identifier: #VU26576
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-9067
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
SmartAX MA5600T
SmartAX MA5800
SmartAX EA5800
Software vendor:
Huawei

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can trigger memory corruption and execute arbitrary code on the target system as an optical line terminal (OLT).

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install updates from vendor's website.

External links