Severity
5.3MEDIUM
EPSS
0.2%
top 59.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateMay 24

Description

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability. An authenticated attacker may do some special operations in the affected products in some special scenarios to exploit the vulnerability. Due to improper race conditions of different operations, successful exploit will lead to Dangling pointer dereference, causing

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages4 packages

CVEListV5huawei/nip6800V500R001C30, V500R001C60SPC500, V500R005C00+2
NVDhuawei/nip6800_firmwarev500r001c30, v500r001c60spc500, v500r005c00+2
NVDhuawei/usg9500_firmware4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-gvmv-7rg8-v686: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600,2022-05-24
CVEList
CVE-2020-1814: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600,2020-02-18
CVE-2020-1814 (MEDIUM CVSS 5.3) | Huawei NIP6800 versions V500R001C30 | cvebase.io