MEDIUM
There is an out-of-bounds read vulnerability in Huawei CloudEngine products
Published Jan 13, 2021
6.5
MEDIUMCVSS 3.1
EPSS 0.33%
Description
There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of bounds read when the system does the certain operation.
Affected products
- Vendor n/a Product CloudEngine 12800;CloudEngine 5800;CloudEngine 6800;CloudEngine 7800 Defaultn/a
- Version V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800,V200R019C10SPC800StatusaffectedConstraints-
- Version V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | CloudEngine 12800;CloudEngine 5800;CloudEngine 6800;CloudEngine 7800 | n/a |
|
Configuration 1
AND
OR
- v200r002c50spc800
- v200r003c00spc810
- v200r005c00spc800
- v200r005c10spc800
- v200r019c00spc800
- v200r019c10spc800
Running on/with
- n/a
Configuration 2
AND
OR
- v200r002c50spc800
- v200r003c00spc810
- v200r005c00spc800
- v200r005c10spc800
- v200r019c00spc800
- v200r019c10spc800
Running on/with
- n/a
Configuration 3
AND
OR
- v200r002c50spc800
- v200r003c00spc810
- v200r005c00spc800
- v200r005c10spc800
- v200r005c20spc800
- v200r019c00spc800
- v200r019c10spc800
Running on/with
- n/a
Configuration 4
AND
OR
- v200r002c50spc800
- v200r003c00spc810
- v200r005c00spc800
- v200r005c10spc800
- v200r019c00spc800
- v200r019c10spc800
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12691 Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201230-02-cloudengine-en x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-12691 | Advisory | |
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201230-02-cloudengine-en | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner huawei
Published Jan 13, 2021
Updated Aug 4, 2024
Reserved Nov 29, 2019
Link CVE-2020-1865
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-12691 Assigner huawei
Published Jan 13, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-12691