There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Huawei
Huawei ips Module Huawei ips Module Firmware Huawei ngfw Module Huawei ngfw Module Firmware Huawei nip6300 Huawei nip6300 Firmware Huawei nip6600 Huawei nip6600 Firmware Huawei nip6800 Huawei nip6800 Firmware Huawei secospace Usg6300 Huawei secospace Usg6300 Firmware Huawei secospace Usg6500 Huawei secospace Usg6500 Firmware Huawei secospace Usg6600 Huawei secospace Usg6600 Firmware Huawei usg6000v Huawei usg6000v Firmware |
|
CPEs | cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6500:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:usg6000v:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r002c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r002c20:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6800_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg6000v_firmware:v500r003c00:*:*:*:*:*:*:* |
|
Vendors & Products |
Huawei
Huawei ips Module Huawei ips Module Firmware Huawei ngfw Module Huawei ngfw Module Firmware Huawei nip6300 Huawei nip6300 Firmware Huawei nip6600 Huawei nip6600 Firmware Huawei nip6800 Huawei nip6800 Firmware Huawei secospace Usg6300 Huawei secospace Usg6300 Firmware Huawei secospace Usg6500 Huawei secospace Usg6500 Firmware Huawei secospace Usg6600 Huawei secospace Usg6600 Firmware Huawei usg6000v Huawei usg6000v Firmware |
Fri, 27 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Dec 2024 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289) The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: huawei
Published: 2024-12-27T10:02:45.710Z
Updated: 2024-12-27T14:57:27.653Z
Reserved: 2019-11-29T00:00:00.000Z
Link: CVE-2020-1818
Vulnrichment
Updated: 2024-12-27T14:57:23.487Z
NVD
Status : Analyzed
Published: 2024-12-27T10:15:06.310
Modified: 2025-01-10T20:28:46.463
Link: CVE-2020-1818
Redhat
No data.