Vulnerability Description
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289) The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ips Module Firmware | v500r001c30 |
| Huawei | Ips Module | - |
| Huawei | Ngfw Module Firmware | v500r002c00 |
| Huawei | Ngfw Module | - |
| Huawei | Nip6300 Firmware | v500r001c30 |
| Huawei | Nip6300 | - |
| Huawei | Nip6600 Firmware | v500r001c30 |
| Huawei | Nip6600 | - |
| Huawei | Nip6800 Firmware | v500r001c60 |
| Huawei | Nip6800 | - |
| Huawei | Secospace Usg6300 Firmware | v500r001c30 |
| Huawei | Secospace Usg6300 | - |
| Huawei | Secospace Usg6500 Firmware | v500r001c30 |
| Huawei | Secospace Usg6500 | - |
| Huawei | Secospace Usg6600 Firmware | v500r001c30 |
| Huawei | Secospace Usg6600 | - |
| Huawei | Usg6000V Firmware | v500r003c00 |
| Huawei | Usg6000V | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2020-1820?
CVE-2020-1820 is a vulnerability with a CVSS score of 3.7 (LOW). There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur ou...
How severe is CVE-2020-1820?
CVE-2020-1820 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1820?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ips Module Firmware, Huawei Ips Module, Huawei Ngfw Module Firmware, Huawei Ngfw Module, Huawei Nip6300 Firmware.