There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Huawei
Huawei ips Module Huawei ips Module Firmware Huawei ngfw Module Huawei ngfw Module Firmware Huawei nip6300 Huawei nip6300 Firmware Huawei nip6600 Huawei nip6600 Firmware Huawei nip6800 Huawei nip6800 Firmware Huawei secospace Usg6300 Huawei secospace Usg6300 Firmware Huawei secospace Usg6500 Huawei secospace Usg6500 Firmware Huawei secospace Usg6600 Huawei secospace Usg6600 Firmware Huawei usg6000v Huawei usg6000v Firmware |
|
CPEs | cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6300:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6500:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:usg6000v:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r002c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r002c20:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6300_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6600_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6800_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6300_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6500_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg6000v_firmware:v500r003c00:*:*:*:*:*:*:* |
|
Vendors & Products |
Huawei
Huawei ips Module Huawei ips Module Firmware Huawei ngfw Module Huawei ngfw Module Firmware Huawei nip6300 Huawei nip6300 Firmware Huawei nip6600 Huawei nip6600 Firmware Huawei nip6800 Huawei nip6800 Firmware Huawei secospace Usg6300 Huawei secospace Usg6300 Firmware Huawei secospace Usg6500 Huawei secospace Usg6500 Firmware Huawei secospace Usg6600 Huawei secospace Usg6600 Firmware Huawei usg6000v Huawei usg6000v Firmware |
Fri, 27 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 27 Dec 2024 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289) The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: huawei
Published: 2024-12-27T10:05:47.224Z
Updated: 2024-12-27T14:56:31.845Z
Reserved: 2019-11-29T00:00:00.000Z
Link: CVE-2020-1819
Vulnrichment
Updated: 2024-12-27T14:56:27.356Z
NVD
Status : Analyzed
Published: 2024-12-27T10:15:09.710
Modified: 2025-01-10T20:32:19.230
Link: CVE-2020-1819
Redhat
No data.