CVE-2020-9101
CVE-2020-9101
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
17 jul 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V500R005C10; NGFW Module versions V500R005C00, V500R005C10; Secospace USG6300 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; Secospace USG6600 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10; USG9500 versions V500R001C30, V500R001C60, V500R005C00, V500R005C10
Produtos afetados
Huawei · IPS ModuleHuawei · NGFW ModuleHuawei · Secospace USG6300Huawei · Secospace USG6500Huawei · Secospace USG6600Huawei · USG9500Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →