ID

VAR-202006-1714


CVE

CVE-2020-9071


TITLE

plural Huawei Out-of-bounds read vulnerabilities in the product

Trust: 0.8

sources: JVNDB: JVNDB-2020-005987

DESCRIPTION

There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device. Successful exploit may cause service abnormal in specific scenario.Affected product versions include:AR120-S versions V200R007C00SPC900,V200R007C00SPCa00. plural Huawei The product contains an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be put into a state. Huawei AR1200 is an enterprise router of Huawei. There are buffer error vulnerabilities in many Huawei products

Trust: 2.16

sources: NVD: CVE-2020-9071 // JVNDB: JVNDB-2020-005987 // CNVD: CNVD-2020-28979

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-28979

AFFECTED PRODUCTS

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar150scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar3600scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spca00

Trust: 1.0

vendor:huaweimodel:ar200-sscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar150scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar200-sscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar120-sscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:srg3300scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar3600scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar150scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar160scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:ar200scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar150scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:srg1300scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar200-sscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spca00

Trust: 1.0

vendor:huaweimodel:ar510scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:netengine16exscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:srg1300scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar3600scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:ar150-sscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:netengine16exscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:srg2300scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar1200-sscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar150-sscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar2200-sscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar3200scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:srg2300scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar1200-sscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar150scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:ar200scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar2200-sscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:srg1300scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar160scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar160scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar200scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:netengine16exscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar150-sscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar160scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:srg3300scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar3600scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:srg2300scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar1200-sscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar160scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar120-sscope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar200scope:eqversion:v200r007c00spcb00pwe

Trust: 1.0

vendor:huaweimodel:ar120-sscope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spc900

Trust: 1.0

vendor:huaweimodel:ar2200-sscope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:ar120-sscope:eqversion:v200r007c00spca00

Trust: 1.0

vendor:huaweimodel:ar3600scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar200scope:eqversion:v200r007c00spcc00

Trust: 1.0

vendor:huaweimodel:srg3300scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spcb00

Trust: 1.0

vendor:huaweimodel:ar1200scope:eqversion:v200r007c00spc900pwe

Trust: 1.0

vendor:huaweimodel:ar2200scope:eqversion:v200r007c00spca00

Trust: 1.0

vendor:huaweimodel:ar120-sscope: - version: -

Trust: 0.8

vendor:huaweimodel:ar1200scope: - version: -

Trust: 0.8

vendor:huaweimodel:ar1200-sscope: - version: -

Trust: 0.8

vendor:huaweimodel:ar150scope: - version: -

Trust: 0.8

vendor:huaweimodel:ar150-sscope: - version: -

Trust: 0.8

vendor:huaweimodel:ar160scope: - version: -

Trust: 0.8

vendor:huaweimodel:ar200scope: - version: -

Trust: 0.8

vendor:huaweimodel:ar200-sscope: - version: -

Trust: 0.8

vendor:huaweimodel:ar2200scope: - version: -

Trust: 0.8

vendor:huaweimodel:ar2200-sscope: - version: -

Trust: 0.8

vendor:huaweimodel:ar3200 v200r007c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3200 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3200 v200r007c00spca00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3200 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3200 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar120-s v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar120-s v200r007c00spca00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar120-s v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar120-s v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spc900pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spca00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200-s v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200-s v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar1200-s v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150-s v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150-s v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar150-s v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar160 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar160 v200r007c00spc900pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar160 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar160 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar160 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200 v200r007c00spc900pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200 v200r007c00spc900pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3600 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3600 v200r007c00spc900pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3600 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3600 v200r007c00spcb00pwescope: - version: -

Trust: 0.6

vendor:huaweimodel:ar3600 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar510 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:netengine16ex v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:netengine16ex v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:netengine16ex v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg1300 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg1300 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg1300 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg2300 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg2300 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg2300 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg3300 v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg3300 v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:srg3300 v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200-s v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200-s v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar200-s v200r007c00spcc00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200-s v200r007c00spc900scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200-s v200r007c00spcb00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ar2200-s v200r007c00spcc00scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-28979 // JVNDB: JVNDB-2020-005987 // NVD: CVE-2020-9071

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9071
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-005987
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-28979
value: LOW

Trust: 0.6

CNNVD: CNNVD-202004-1128
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-9071
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-005987
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-28979
severity: LOW
baseScore: 1.8
vectorString: AV:A/AC:H/AU:N/C:N/I:N/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.2
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-9071
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-005987
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-28979 // JVNDB: JVNDB-2020-005987 // CNNVD: CNNVD-202004-1128 // NVD: CVE-2020-9071

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.8

sources: JVNDB: JVNDB-2020-005987 // NVD: CVE-2020-9071

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202004-1128

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202004-1128

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-005987

PATCH

title:huawei-sa-20200415-01-ooburl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-01-oob-en

Trust: 0.8

title:Patch for Multiple Huawei products cross-border reading vulnerability (CNVD-2020-28979)url:https://www.cnvd.org.cn/patchInfo/show/218005

Trust: 0.6

title:Multiple Huawei Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=116855

Trust: 0.6

sources: CNVD: CNVD-2020-28979 // JVNDB: JVNDB-2020-005987 // CNNVD: CNNVD-202004-1128

EXTERNAL IDS

db:NVDid:CVE-2020-9071

Trust: 3.0

db:JVNDBid:JVNDB-2020-005987

Trust: 0.8

db:CNVDid:CNVD-2020-28979

Trust: 0.6

db:CNNVDid:CNNVD-202004-1128

Trust: 0.6

sources: CNVD: CNVD-2020-28979 // JVNDB: JVNDB-2020-005987 // CNNVD: CNNVD-202004-1128 // NVD: CVE-2020-9071

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-01-oob-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-9071

Trust: 1.4

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200415-01-oob-cn

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9071

Trust: 0.8

sources: CNVD: CNVD-2020-28979 // JVNDB: JVNDB-2020-005987 // CNNVD: CNNVD-202004-1128 // NVD: CVE-2020-9071

SOURCES

db:CNVDid:CNVD-2020-28979
db:JVNDBid:JVNDB-2020-005987
db:CNNVDid:CNNVD-202004-1128
db:NVDid:CVE-2020-9071

LAST UPDATE DATE

2024-11-23T22:55:07.635000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-28979date:2020-05-19T00:00:00
db:JVNDBid:JVNDB-2020-005987date:2020-06-25T00:00:00
db:CNNVDid:CNNVD-202004-1128date:2020-06-04T00:00:00
db:NVDid:CVE-2020-9071date:2024-11-21T05:39:58.290

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-28979date:2020-05-19T00:00:00
db:JVNDBid:JVNDB-2020-005987date:2020-06-25T00:00:00
db:CNNVDid:CNNVD-202004-1128date:2020-04-15T00:00:00
db:NVDid:CVE-2020-9071date:2020-06-01T15:15:14.840