CVE-2020-1866 - CVE House
Back to Database
Status published Medium CVE-2020-1866

There is an out-of-bounds read vulnerability in several products. The...

Vulnerability Description

There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-1866

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

NIP6800;S12700;S2700;S5700;S6700;S7700;S9700;Secospace USG6600;USG9500
Vulnerable Versions:
V500R001C30,V500R001C60SPC500,V500R005C00, V200R008C00, V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00, V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00

Timeline

Official Publish: January 13th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.