CVE-2020-36602
6.1
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.9 / Impact: 5.2
Source: NVD
Description
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause out-of-bounds read and write.
Affected (45)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.576 |
| Running on/with | Platform Versions |
|---|---|
Huawei 576up005 Hota Cm H Shark Bd | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.577 |
| Running on/with | Platform Versions |
|---|---|
Huawei 577hota Cm H Shark Bd | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.581 |
| Running on/with | Platform Versions |
|---|---|
Huawei 581up Hota Cm H Shark Bd | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.586 |
| Running on/with | Platform Versions |
|---|---|
Huawei 586 Hota Cm H Shark Bd | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.588 |
| Running on/with | Platform Versions |
|---|---|
Huawei 588 Hota Cm H Shark Bd | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.606 |
| Running on/with | Platform Versions |
|---|---|
Huawei 606 Hota Cm H Shark Bd | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.1 |
| Running on/with | Platform Versions |
|---|---|
Huawei Bi Acc Report | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0.106 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cm H Shark Bd | All versions |
Related CWEs
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.