Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Attackers can send specific message to cause double free memory. This may compromise normal service.
2020-02-17T21:15:12.850
2024-11-21T05:11:26.960
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei | nip6800_firmware | v500r001c30 | Yes |
Operating System | huawei | nip6800_firmware | v500r001c60spc500 | Yes |
Hardware | huawei | nip6800 | - | No |
Operating System | huawei | secospace_usg6600_firmware | v500r001c30spc200 | Yes |
Operating System | huawei | secospace_usg6600_firmware | v500r001c30spc600 | Yes |
Operating System | huawei | secospace_usg6600_firmware | v500r001c60spc500 | Yes |
Hardware | huawei | secospace_usg6600 | - | No |
Operating System | huawei | usg9500_firmware | v500r001c30spc200 | Yes |
Operating System | huawei | usg9500_firmware | v500r001c30spc600 | Yes |
Operating System | huawei | usg9500_firmware | v500r001c60spc500 | Yes |
Hardware | huawei | usg9500 | - | No |