CVE-2020-1874

MEDIUM

NIP6800, Secospace USG6600, USG9500 <V500R001C30; V500R001C60SPC500...

Title source: llm
STIX 2.1

Description

NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-824
Status published
Products (11)
huawei/nip6800_firmware v500r001c30
huawei/nip6800_firmware v500r001c60spc500
huawei/nip6800_firmware v500r005c00spc100
huawei/secospace_usg6600_firmware v500r001c30spc200
huawei/secospace_usg6600_firmware v500r001c30spc600
huawei/secospace_usg6600_firmware v500r001c60spc500
huawei/secospace_usg6600_firmware v500r005c00spc100
huawei/usg9500_firmware v500r001c30spc200
huawei/usg9500_firmware v500r001c30spc600
huawei/usg9500_firmware v500r001c60spc500
... and 1 more
Published Feb 28, 2020
Tracked Since Feb 18, 2026