HIGH · 7.5

CVE-2020-9098

Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the in...

Vulnerability Description

Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the insufficient validation of some parameter, successful exploit could cause device reboot.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiOceanstor 5310 Firmwarev500r007c60spc100
HuaweiOceanstor 5310v5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9098?

CVE-2020-9098 is a vulnerability with a CVSS score of 7.5 (HIGH). Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the in...

How severe is CVE-2020-9098?

CVE-2020-9098 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9098?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Oceanstor 5310 Firmware, Huawei Oceanstor 5310.