PT-2020-5960 · Huawei · Cloudengine 12800+7
Published
2020-05-27
·
Updated
2020-11-19
·
CVE-2020-1870
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
CloudEngine 12800 versions V200R019C00SPC800
CloudEngine 5800 versions V200R019C00SPC800
CloudEngine 6800 versions V200R005C20SPC800 through V200R019C00SPC800
CloudEngine 7800 versions V200R019C00SPC800
NE40E versions V800R011C00SPC200 through V800R011C10SPC100
NE40E-F versions V800R011C00SPC200 through V800R011C10SPC100
NE40E-M versions V800R011C00SPC200 through V800R011C10SPC100
Description
The issue is related to improper memory management, which may cause memory leakage in certain cases. Attackers can exploit this by performing a series of operations, potentially leading to a denial of service.
Recommendations
For CloudEngine 12800 version V200R019C00SPC800, update to a version that includes the fix for this issue.
For CloudEngine 5800 version V200R019C00SPC800, update to a version that includes the fix for this issue.
For CloudEngine 6800 versions V200R005C20SPC800 through V200R019C00SPC800, update to a version that includes the fix for this issue.
For CloudEngine 7800 version V200R019C00SPC800, update to a version that includes the fix for this issue.
For NE40E versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue.
For NE40E-F versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue.
For NE40E-M versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the affected products until a patch is available.
Fix
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Huawei Vrp
Ne40E
Ne40E-F
Ne40E-M