CVE-2020-9101

Severity
6.5MEDIUM
EPSS
0.0%
top 89.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 24

Description

There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V500R005C10; NGFW Module versions V500R005C00, V500R005C10; Secospace USG6300 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages12 packages

CVEListV5huawei/secospace_usg63004 versions+3
CVEListV5huawei/secospace_usg65004 versions+3
CVEListV5huawei/secospace_usg66004 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-vqmw-xc69-r5c5: There is an out-of-bounds write vulnerability in some products2022-05-24
CVEList
CVE-2020-9101: There is an out-of-bounds write vulnerability in some products2020-07-17