CVE-2020-1881
published 2020-02-28CVE-2020-1881: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have a resource management error…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.79%
52.3th percentile
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have a resource management error vulnerability. An attacker needs to perform specific operations to trigger a function of the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | nip6800_firmware | — | — |
| huawei | oceanstor_5310_firmware | — | — |
| huawei | secospace_usg6600_firmware | — | — |
| huawei | secospace_usg6600_firmware | — | — |
| huawei | usg9500_firmware | — | — |
| huawei | usg9500_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT AnyDesk UDP Discovery Format String (CVE-2020-13160)
suricata·2020-06-16·CVSS 9.8
CVE-2020-13160 [CRITICAL] ET EXPLOIT AnyDesk UDP Discovery Format String (CVE-2020-13160)
ET EXPLOIT AnyDesk UDP Discovery Format String (CVE-2020-13160)
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 50001 (msg:"ET EXPLOIT AnyDesk UDP Discovery Format String (CVE-2020-13160)"; isdataat:16; content:"|3e d1|"; depth:2; byte_test:4,>,16,11,relative,big; pcre:"/^.{11}([\xC0-\xC1]|[\xF5-\xFF]|\xE0[\x80-\x9F]|\xF0[\x80-\x8F]|[\xC2-\xDF](?![\x80-\xBF])|[\xE0-\xEF](?![\x80-\xBF]{2})|[\xF0-\xF4](?![\x80-\xBF]{3})|(?<=[\x00-\x7F\xF5-\xFF])[\x80-\xBF]|(?<![\xC2-\xDF]|[\xE0-\xEF]|[\xE0-\xEF][\x80-\xBF]|[\xF0-\xF4]|[\xF0-\xF4][\x80-\xBF]|[\xF0-\xF4][\x80-\xBF]{2})[\x80-\xBF]|(?<=[\xE0-\xEF])[\x80-\xBF](?![\x80-\xBF])|(?<=[\xF0-\xF4])[\x80-\xBF](?![\x80-\xBF]{2})|(?<=[\xF0-\xF4][\x80-\xBF])[\x80-\xBF](?![\x80-\xBF]))/R"; reference:url,devel0pment.de/?p=1881; reference:cve,2020-13160; class
No writeups or analysis indexed.
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invalidpointer-enhttps://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-02-resource-enhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invalidpointer-enhttps://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-02-resource-en
2020-02-28
Published