CVE Vulnerabilities

CVE-2020-9085

NULL Pointer Dereference

Published: Dec 27, 2024 | Modified: Jan 13, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to insufficient validation of some parameter in the message, successful exploit may cause some process abnormal. (Vulnerability ID: HWPSIRT-2017-10105)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9085.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
B612_firmware Huawei b612s-25dtcpu-v100r001b192d03sp00c234 (including) b612s-25dtcpu-v100r001b192d03sp00c234 (including)
B612_firmware Huawei b612s-25dtcpu-v100r001b192d03sp00c287 (including) b612s-25dtcpu-v100r001b192d03sp00c287 (including)
B612_firmware Huawei b612s-25dtcpu-v100r001b192d05sp00c00 (including) b612s-25dtcpu-v100r001b192d05sp00c00 (including)

Potential Mitigations

References