CVE-2020-1828
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
17/02/2020
Last modified:
21/07/2021
Description
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message. Attackers can send specific message to cause out-of-bound read, compromising normal service.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:nip6800_firmware:v500r001c30:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:nip6800_firmware:v500r001c60spc500:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c30spc200:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c30spc600:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c60spc500:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:usg9500_firmware:v500r001c30spc200:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:usg9500_firmware:v500r001c30spc600:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:usg9500_firmware:v500r001c60spc500:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:usg9500_firmware:v500r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:usg9500:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



