CVE-2020-1866
Summary
| CVE | CVE-2020-1866 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-13 23:15:00 UTC |
| Updated | 2021-01-19 17:12:00 UTC |
| Description | There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Nip6800 | - | All | All | All |
| Hardware | Huawei | Nip6800 | - | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r001c30 | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r005c00 | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r001c30 | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Nip6800 Firmware | v500r005c00 | All | All | All |
| Hardware | Huawei | S12700 | - | All | All | All |
| Hardware | Huawei | S12700 | - | All | All | All |
| Operating System | Huawei | S12700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S12700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | S2700 | - | All | All | All |
| Hardware | Huawei | S2700 | - | All | All | All |
| Operating System | Huawei | S2700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S2700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | S5700 | - | All | All | All |
| Hardware | Huawei | S5700 | - | All | All | All |
| Operating System | Huawei | S5700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S5700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | S6700 | - | All | All | All |
| Hardware | Huawei | S6700 | - | All | All | All |
| Operating System | Huawei | S6700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S6700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | S7700 | - | All | All | All |
| Hardware | Huawei | S7700 | - | All | All | All |
| Operating System | Huawei | S7700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S7700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | S9700 | - | All | All | All |
| Hardware | Huawei | S9700 | - | All | All | All |
| Operating System | Huawei | S9700 Firmware | v200r008c00 | All | All | All |
| Operating System | Huawei | S9700 Firmware | v200r008c00 | All | All | All |
| Hardware | Huawei | Secospace Usg6600 | - | All | All | All |
| Hardware | Huawei | Secospace Usg6600 | - | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c30spc200 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c30spc600 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r005c00 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c30spc200 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c30spc600 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Secospace Usg6600 Firmware | v500r005c00 | All | All | All |
| Hardware | Huawei | Usg9500 | - | All | All | All |
| Hardware | Huawei | Usg9500 | - | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c30spc300 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c30spc600 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r005c00 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c30spc300 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c30spc600 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r001c60spc500 | All | All | All |
| Operating System | Huawei | Usg9500 Firmware | v500r005c00 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Out of Bounds Read Vulnerability in Several Products | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43882 Huawei Switch Out-of-bounds Read Vulnerability (Huawei-SA-20200122-09)