CVE-2020-1876

HIGH

NIP6800;Secospace USG6600;USG9500 <V500R001C30; V500R001C60SPC500; ...

Title source: llm
STIX 2.1

Description

NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write vulnerability. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0018
EPSS Percentile 39.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (10)
huawei/nip6800_firmware v500r001c30
huawei/nip6800_firmware v500r001c60spc500
huawei/nip6800_firmware v500r005c00
huawei/secospace_usg6600_firmware v500r001c30spc600
huawei/secospace_usg6600_firmware v500r001c60spc500
huawei/secospace_usg6600_firmware v500r005c00
huawei/usg9500_firmware v500r001c30spc200
huawei/usg9500_firmware v500r001c30spc600
huawei/usg9500_firmware v500r001c60spc500
huawei/usg9500_firmware v500r005c00
Published Feb 28, 2020
Tracked Since Feb 18, 2026