Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-1873

NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the device reboot.

  • Published: Feb 28, 2020
  • Updated: Apr 13, 2023
  • CVE: CVE-2020-1873
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: High
  • Score: 7.8
  • AV:N/AC:L/Au:N/C:N/I:N/A:C

CWEs:

Software From Fixed in
huawei / nip6800_firmware 500r001c30 500r001c30.x
huawei / nip6800_firmware 500r001c60spc500 500r001c60spc500.x
huawei / nip6800_firmware 500r005c00spc100 500r005c00spc100.x
huawei / secospace_usg6600_firmware 500r001c30spc200 500r001c30spc200.x
huawei / secospace_usg6600_firmware 500r001c30spc600 500r001c30spc600.x
huawei / secospace_usg6600_firmware 500r001c60spc500 500r001c60spc500.x
huawei / secospace_usg6600_firmware 500r005c00spc100 500r005c00spc100.x
huawei / usg9500_firmware 500r001c30spc200 500r001c30spc200.x
huawei / usg9500_firmware 500r001c30spc600 500r001c30spc600.x
huawei / usg9500_firmware 500r001c60spc500 500r001c60spc500.x
huawei / usg9500_firmware 500r005c00spc100 500r005c00spc100.x