6.5
CVSSv3

CVE-2020-1865

Published: 13/01/2021 Updated: 19/01/2021
CVSS v2 Base Score: 3.3 | Impact Score: 2.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 294
Vector: AV:A/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of bounds read when the system does the certain operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei cloudengine_12800_firmware v200r002c50spc800

huawei cloudengine_12800_firmware v200r003c00spc810

huawei cloudengine_12800_firmware v200r005c00spc800

huawei cloudengine_12800_firmware v200r005c10spc800

huawei cloudengine_12800_firmware v200r019c00spc800

huawei cloudengine_12800_firmware v200r019c10spc800

huawei cloudengine_5800_firmware v200r002c50spc800

huawei cloudengine_5800_firmware v200r003c00spc810

huawei cloudengine_5800_firmware v200r005c00spc800

huawei cloudengine_5800_firmware v200r005c10spc800

huawei cloudengine_5800_firmware v200r019c00spc800

huawei cloudengine_5800_firmware v200r019c10spc800

huawei cloudengine_6800_firmware v200r002c50spc800

huawei cloudengine_6800_firmware v200r003c00spc810

huawei cloudengine_6800_firmware v200r005c00spc800

huawei cloudengine_6800_firmware v200r005c10spc800

huawei cloudengine_6800_firmware v200r005c20spc800

huawei cloudengine_6800_firmware v200r019c00spc800

huawei cloudengine_6800_firmware v200r019c10spc800

huawei cloudengine_7800_firmware v200r002c50spc800

huawei cloudengine_7800_firmware v200r003c00spc810

huawei cloudengine_7800_firmware v200r005c00spc800

huawei cloudengine_7800_firmware v200r005c10spc800

huawei cloudengine_7800_firmware v200r019c00spc800

huawei cloudengine_7800_firmware v200r019c10spc800