CVE-2020-9071

MEDIUMCVSS 6.5/10EPSS 0.63%

Last modified

CVE-2020-9071 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. EPSS estimates a 0.63% chance of exploitation in the next 30 days.

Description

There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.63%

45.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiAr120-S Firmwarev200r007c00spc900
HuaweiAr120-S Firmwarev200r007c00spca00
HuaweiAr120-S Firmwarev200r007c00spcb00
HuaweiAr120-S Firmwarev200r007c00spcc00
HuaweiAr1200 Firmwarev200r007c00spc900
HuaweiAr1200 Firmwarev200r007c00spc900pwe
HuaweiAr1200 Firmwarev200r007c00spca00
HuaweiAr1200 Firmwarev200r007c00spcb00
HuaweiAr1200 Firmwarev200r007c00spcb00pwe
HuaweiAr1200 Firmwarev200r007c00spcc00
HuaweiAr1200-S Firmwarev200r007c00spc900
HuaweiAr1200-S Firmwarev200r007c00spcb00
HuaweiAr1200-S Firmwarev200r007c00spcc00
HuaweiAr150 Firmwarev200r007c00spc900
HuaweiAr150 Firmwarev200r007c00spc900pwe
HuaweiAr150 Firmwarev200r007c00spcb00
HuaweiAr150 Firmwarev200r007c00spcb00pwe
HuaweiAr150 Firmwarev200r007c00spcc00
HuaweiAr150-S Firmwarev200r007c00spc900
HuaweiAr150-S Firmwarev200r007c00spcb00
HuaweiAr150-S Firmwarev200r007c00spcc00
HuaweiAr160 Firmwarev200r007c00spc900
HuaweiAr160 Firmwarev200r007c00spc900pwe
HuaweiAr160 Firmwarev200r007c00spcb00
HuaweiAr160 Firmwarev200r007c00spcb00pwe
HuaweiAr160 Firmwarev200r007c00spcc00
HuaweiAr200 Firmwarev200r007c00spc900
HuaweiAr200 Firmwarev200r007c00spc900pwe
HuaweiAr200 Firmwarev200r007c00spcb00
HuaweiAr200 Firmwarev200r007c00spcb00pwe
HuaweiAr200 Firmwarev200r007c00spcc00
HuaweiAr200-S Firmwarev200r007c00spc900
HuaweiAr200-S Firmwarev200r007c00spcb00
HuaweiAr200-S Firmwarev200r007c00spcc00
HuaweiAr2200 Firmwarev200r007c00spc900
HuaweiAr2200 Firmwarev200r007c00spc900pwe
HuaweiAr2200 Firmwarev200r007c00spca00
HuaweiAr2200 Firmwarev200r007c00spcb00
HuaweiAr2200 Firmwarev200r007c00spcb00pwe
HuaweiAr2200 Firmwarev200r007c00spcc00
HuaweiAr2200-S Firmwarev200r007c00spc900
HuaweiAr2200-S Firmwarev200r007c00spcb00
HuaweiAr2200-S Firmwarev200r007c00spcc00
HuaweiAr3200 Firmwarev200r007c00
HuaweiAr3200 Firmwarev200r007c00spc900
HuaweiAr3200 Firmwarev200r007c00spc900pwe
HuaweiAr3200 Firmwarev200r007c00spca00
HuaweiAr3200 Firmwarev200r007c00spcb00
HuaweiAr3200 Firmwarev200r007c00spcb00pwe
HuaweiAr3200 Firmwarev200r007c00spcc00

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-9071?
There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00
How severe is CVE-2020-9071?
CVE-2020-9071 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.63% probability of exploitation in the next 30 days.
How do I fix CVE-2020-9071?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-9071?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST