CVE-2020-9105
MEDIUMHuawei Taurus-AN00B Firmware < 10.1.0.156(C00E155R7P2) - Memory Access and Modification via Input Validation Bypass
Title source: llmDescription
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to access and modify the memory of the device by doing a series of operations. Successful exploit may cause the service abnormal.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200923-01-outofbound-en
Scores
CVSS v3
6.7
EPSS
0.0003
EPSS Percentile
7.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (1)
huawei/taurus-an00b_firmware
< 10.1.0.156\(c00e155r7p2\)
Published
Oct 09, 2020
Tracked Since
Feb 18, 2026