← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-9071

There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
EPSS Probability:0.63%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
huawei ar120-s_firmware v200r007c00spc900, v200r007c00spca00, v200r007c00spcb00, v200r007c00spcc00
huawei ar120-s all
huawei ar1200_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spca00, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar1200 all
huawei ar1200-s_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei ar1200-s all
huawei ar150_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar150 all
huawei ar150-s_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei ar150-s all
huawei ar160_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar160 all
huawei ar200_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar200 all
huawei ar200-s_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei ar200-s all
huawei ar2200_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spca00, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar2200 all
huawei ar2200-s_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei ar2200-s all
huawei ar3200_firmware v200r007c00, v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spca00, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar3200 all
huawei ar3600_firmware v200r007c00spc900, v200r007c00spc900pwe, v200r007c00spcb00, v200r007c00spcb00pwe, v200r007c00spcc00
huawei ar3600 all
huawei ar510_firmware v200r007c00spc900
huawei ar510 all
huawei netengine16ex_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei netengine16ex all
huawei srg1300_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei srg1300 all
huawei srg2300_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei srg2300 all
huawei srg3300_firmware v200r007c00spc900, v200r007c00spcb00, v200r007c00spcc00
huawei srg3300 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.634%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHuawei Technologies · Vendor · China
Reserved2020-02-18T00:00:00
Published2020-06-01T14:02:46
Last Updated2024-08-04T10:19:19

LINK COPIED TO CLIPBOARD