CVE-2020-1824: Huawei Ips Module Firmware

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289) The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.

Affected products

  • Huawei Ips Module Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei Ngfw Module Firmware: version v500r002c00 only; version v500r002c20 only; version v500r005c00 only
  • Huawei NIP6300 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei NIP6600 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei NIP6800 Firmware: version v500r001c60 only; version v500r005c00 only
  • Huawei Secospace USG6300 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei Secospace USG6500 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei Secospace USG6600 Firmware: version v500r001c30 only; version v500r005c00 only
  • Huawei USG6000V Firmware: version v500r003c00 only

Published 2024-12-28. Last modified 2026-06-17.