CVE Vulnerabilities

CVE-2020-9086

Buffer Underwrite ('Buffer Underflow')

Published: Dec 27, 2024 | Modified: Jan 13, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID: HWPSIRT-2017-08234)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9086.

Weakness 

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software 

Name Vendor Start Version End Version
B612_firmware Huawei b612s-25dtcpu-v100r001b192d03sp00c234 (including) b612s-25dtcpu-v100r001b192d03sp00c234 (including)
B612_firmware Huawei b612s-25dtcpu-v100r001b192d03sp00c287 (including) b612s-25dtcpu-v100r001b192d03sp00c287 (including)
B612_firmware Huawei b612s-25dtcpu-v100r001b192d05sp00c00 (including) b612s-25dtcpu-v100r001b192d05sp00c00 (including)

Potential Mitigations 

References