PT-2020-20503 · Huawei · E6878-870+1
Published
2020-10-19
·
Updated
2020-10-29
·
CVE-2020-9111
CVSS v3.1
4.5
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
E6878-370 versions 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP21C233)
E6878-870 versions 10.0.3.1(H557SP27C233), 10.0.3.1(H563SP11C233)
Description
The system has a denial of service issue due to improper event checking. An attacker could continually launch certain events, potentially causing the process to reboot.
Recommendations
For E6878-370 versions 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP21C233), update to a version that properly checks events to prevent denial of service.
For E6878-870 versions 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP11C233), update to a version that properly checks events to prevent denial of service.
As a temporary workaround, consider restricting the ability to launch certain events to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E6878-370
E6878-870