PT-2020-15071 · Huawei · E6878-370
Published
2020-05-21
·
Updated
2020-05-21
·
CVE-2020-1799
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
E6878-370 versions 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP1C00), 10.0.3.1(H563SP1C233)
Description
The software has a use after free issue, where it references memory after it has been freed in certain scenarios. An attacker can exploit this by performing a series of crafted operations through the web portal, potentially leading to malicious code execution.
Recommendations
For versions 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP1C00), 10.0.3.1(H563SP1C233), consider restricting access to the web portal until a fix is available.
As a temporary workaround, avoid using the web portal for critical operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E6878-370