This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
There is a denial of service vulnerability in some Huawei products. Due to improper memory management, memory leakage may occur in some special cases. Attackers can perform a series of operations to exploit this vulnerability. Successful exploit may cause a denial of service. (Vulnerability ID: HWPSIRT-2020-02210)
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-01-dos-en
Product Name |
Affected Version |
Resolved Product and Version |
CloudEngine 12800 |
V200R019C00SPC800 |
V200R019C10SPC800 |
CloudEngine 5800 |
V200R019C00SPC800 |
V200R019C10SPC800 |
CloudEngine 6800 |
V200R005C20SPC800 |
V200R019C10SPC800 |
V200R019C00SPC800 |
||
CloudEngine 7800 |
V200R019C00SPC800 |
V200R019C10SPC800 |
NE40E |
V800R011C00SPC200 |
V800R011SPH037 |
V800R011C00SPC300 |
V800R012C00SPC300 |
|
V800R011C10SPC100 |
V800R011SPH037 |
|
NE40E-F |
V800R011C00SPC200 |
V800R011SPH036 |
V800R011C10SPC100 |
||
NE40E-M |
V800R011C00SPC200 |
V800R011SPH036 |
V800R011C10SPC100 |
Successful exploit may cause a denial of service.
The vulnerability classification has been performed by using the CVSSv3 scoring system (http://www.first.org/cvss/specification-document).
Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Temporal Score: 5.5 (E:F/RL:O/RC:C)
This vulnerability can be exploited only when the following conditions are present:
Attackers can gain access to the device network.
Vulnerability details:
There is a denial of service vulnerability in some Huawei products. Due to improper memory management, memory leakage may occur in some special cases. Attackers can perform a series of operations to exploit this vulnerability. Successful exploit may cause a denial of service.
Customers should contact Huawei TAC (Huawei Technical Assistance Center) to request the upgrades. For TAC contact information, please refer to Huawei worldwide website at http://www.huawei.com/en/psirt/report-vulnerabilities.
This vulnerability was discovered by Huawei internal tester.
2020-11-11 V1.3 UPDATED Updated the "Software Versions and Fixes" section;
2020-06-24 V1.2 UPDATED Updated the "Software Versions and Fixes" section; Updated the information in "Summary", "Impact" and "Technical Details";
2020-06-10 V1.1 UPDATED Updated the "Software Versions and Fixes" section;
2020-05-27 V1.0 INITIAL
None