Vulnerability Description
Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the insufficient validation of some parameter, successful exploit could cause device reboot.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Oceanstor 5310 Firmware | v500r007c60spc100 |
| Huawei | Oceanstor 5310 | v5 |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invalidVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invaliVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invalidVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-invaliVendor Advisory
FAQ
What is CVE-2020-9098?
CVE-2020-9098 is a vulnerability with a CVSS score of 7.5 (HIGH). Huawei OceanStor 5310 product with version of V500R007C60SPC100 has an invalid pointer access vulnerability. The software system access an invalid pointer when attacker malformed packet. Due to the in...
How severe is CVE-2020-9098?
CVE-2020-9098 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9098?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Oceanstor 5310 Firmware, Huawei Oceanstor 5310.