CVE-2020-1819
Description
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple out-of-bounds read vulnerabilities in the COPS protocol implementation of Huawei IPS Module allow remote attackers to disrupt service via crafted packets.
Vulnerability
Multiple out-of-bounds (OOB) read vulnerabilities exist in the Common Open Policy Service (COPS) protocol implementation of Huawei IPS Module. The specific decoding function reads out-of-bounds when processing a crafted incoming data packet. Affected versions include V500R001C30, V500R001C60, and V500R005C00 (among others) of the IPS Module. These vulnerabilities are tracked as HWPSIRT-2018-12275 through HWPSIRT-2018-12280 and HWPSIRT-2018-12289 [1].
Exploitation
An attacker can exploit these vulnerabilities by sending a specially crafted COPS packet to an affected device. No authentication is required; the attacker only needs network access to the device. The OOB read occurs during packet decoding, potentially causing a denial of service [1].
Impact
Successful exploitation disrupts the service on the affected device, leading to a denial of service. The exact impact is limited to service disruption; no remote code execution or information disclosure is indicated in the advisory [1].
Mitigation
Huawei has released software updates to fix these vulnerabilities. The resolved version for the IPS Module is V500R005C20SPC500. Users should apply the updates to mitigate the risk. Refer to the Huawei security advisory for full details [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- Range: V500R001C30
- Range: V500R002C00
- Huawei/NIP6800v5Range: V500R001C60
- Range: V500R001C30
- Range: V500R001C30
- Range: V500R001C30
- Huawei/USG6000Vv5Range: V500R003C00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.