PT-2020-5960 · Huawei · Cloudengine 12800+7

Published

2020-05-27

·

Updated

2020-11-19

·

CVE-2020-1870

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions CloudEngine 12800 versions V200R019C00SPC800 CloudEngine 5800 versions V200R019C00SPC800 CloudEngine 6800 versions V200R005C20SPC800 through V200R019C00SPC800 CloudEngine 7800 versions V200R019C00SPC800 NE40E versions V800R011C00SPC200 through V800R011C10SPC100 NE40E-F versions V800R011C00SPC200 through V800R011C10SPC100 NE40E-M versions V800R011C00SPC200 through V800R011C10SPC100
Description The issue is related to improper memory management, which may cause memory leakage in certain cases. Attackers can exploit this by performing a series of operations, potentially leading to a denial of service.
Recommendations For CloudEngine 12800 version V200R019C00SPC800, update to a version that includes the fix for this issue. For CloudEngine 5800 version V200R019C00SPC800, update to a version that includes the fix for this issue. For CloudEngine 6800 versions V200R005C20SPC800 through V200R019C00SPC800, update to a version that includes the fix for this issue. For CloudEngine 7800 version V200R019C00SPC800, update to a version that includes the fix for this issue. For NE40E versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue. For NE40E-F versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue. For NE40E-M versions V800R011C00SPC200 through V800R011C10SPC100, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the affected products until a patch is available.

Fix

DoS

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02135
CVE-2020-1870

Affected Products

Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Huawei Vrp
Ne40E
Ne40E-F
Ne40E-M