CVE-2020-1815 Information

Description

Huawei NIP6800 versions V500R001C30 V500R001C60SPC500 and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200 V500R001C30SPC600 V500R001C60SPC500 and V500R005C00 have a memory leak vulnerability. The software does not sufficiently track and release allocated memory while parse certain message the attacker sends the message continuously that could consume remaining memory. Successful exploit could cause memory exhaust.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Reference

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200212-02-firewall-en

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

7.5

Share on: