← Volver a CVEs
CVE-2020-9124
HIGH7.5
Descripcion
There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause memory leak.
Detalles CVE
Puntuacion CVSS v3.17.5
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado12/29/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
huawei:cloudengine_12800huawei:cloudengine_12800_firmwarehuawei:cloudengine_5800huawei:cloudengine_5800_firmwarehuawei:cloudengine_6800huawei:cloudengine_6800_firmwarehuawei:cloudengine_7800huawei:cloudengine_7800_firmware
Debilidades (CWE)
CWE-401
Referencias
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201223-01-cloudengine-en(psirt@huawei.com)
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201223-01-cloudengine-en(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.