Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-9201

There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.

  • Published: Dec 24, 2020
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-9201
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Low
  • Score: 3.3
  • AV:A/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
huawei / nip6800_firmware 500r001c30 500r001c30.x
huawei / nip6800_firmware 500r001c60spc500 500r001c60spc500.x
huawei / nip6800_firmware 500r005c00 500r005c00.x
huawei / secospace_usg6600_firmware 500r001c30spc200 500r001c30spc200.x
huawei / secospace_usg6600_firmware 500r001c30spc600 500r001c30spc600.x
huawei / secospace_usg6600_firmware 500r001c60spc500 500r001c60spc500.x
huawei / secospace_usg6600_firmware 500r005c00 500r005c00.x
huawei / usg9500_firmware 500r001c30spc200 500r001c30spc200.x
huawei / usg9500_firmware 500r001c30spc600 500r001c30spc600.x
huawei / usg9500_firmware 500r001c60spc500 500r001c60spc500.x
huawei / usg9500_firmware 500r005c00 500r005c00.x