There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.

Project Subscriptions

Vendors Products
Nip6800 Subscribe
Nip6800 Firmware Subscribe
S12700 Firmware Subscribe
S2700 Firmware Subscribe
S5700 Firmware Subscribe
S6700 Firmware Subscribe
S7700 Firmware Subscribe
S9700 Firmware Subscribe
Secospace Usg6600 Subscribe
Secospace Usg6600 Firmware Subscribe
Usg9500 Subscribe
Usg9500 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-12692 There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T06:53:59.744Z

Reserved: 2019-11-29T00:00:00

Link: CVE-2020-1866

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-13T23:15:13.367

Modified: 2024-11-21T05:11:30.670

Link: CVE-2020-1866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses