cbcvebase.
CVE-2020-1877
published 2020-02-28

CVE-2020-1877: NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software…

PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.20%
10.1th percentile
NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful exploit could cause certain process reboot.

Affected

11 ranges
VendorProductVersion rangeFixed in
huaweinip6800_firmware
huaweinip6800_firmware
huaweinip6800_firmware
huaweisecospace_usg6600_firmware
huaweisecospace_usg6600_firmware
huaweisecospace_usg6600_firmware
huaweisecospace_usg6600_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.