CVE-2020-9085

MEDIUM

Huawei B612 Firmware - Denial of Service via NULL Pointer Dereference

Title source: llm
STIX 2.1

Description

There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal. (Vulnerability ID: HWPSIRT-2017-10105) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9085.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 23.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (3)
huawei/b612_firmware b612s-25dtcpu-v100r001b192d03sp00c234
huawei/b612_firmware b612s-25dtcpu-v100r001b192d03sp00c287
huawei/b612_firmware b612s-25dtcpu-v100r001b192d05sp00c00
Published Dec 27, 2024
Tracked Since Feb 18, 2026