Vulnerability Description
NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Nip6800 Firmware | v500r001c30 |
| Huawei | Nip6800 | - |
| Huawei | Secospace Usg6600 Firmware | v500r001c30spc200 |
| Huawei | Secospace Usg6600 | - |
| Huawei | Usg9500 Firmware | v500r001c30spc200 |
| Huawei | Usg9500 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-02-invaliVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-02-invaliVendor Advisory
FAQ
What is CVE-2020-1874?
CVE-2020-1874 is a vulnerability with a CVSS score of 5.5 (MEDIUM). NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when...
How severe is CVE-2020-1874?
CVE-2020-1874 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1874?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Nip6800 Firmware, Huawei Nip6800, Huawei Secospace Usg6600 Firmware, Huawei Secospace Usg6600, Huawei Usg9500 Firmware.