CVE-2020-1820
Description
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple OOB read vulnerabilities in Huawei COPS protocol decoding can cause denial of service on affected products.
Vulnerability
Multiple out-of-bounds (OOB) read vulnerabilities exist in the Common Open Policy Service (COPS) protocol implementation of certain Huawei products [1]. The flaws reside in the specific decoding function that processes incoming COPS data packets. Affected products include the IPS Module running versions V500R001C30, V500R001C60, and V500R005C00 [1]. The vulnerabilities are tracked under CVE-2020-1818 through CVE-2020-1824, with this entry covering CVE-2020-1820 [1].
Exploitation
An attacker can exploit these vulnerabilities by sending a specially crafted COPS packet to an affected device [1]. No prior authentication is required; the attacker only needs network access to deliver the malicious packet. The decoding function fails to properly validate input lengths, leading to an out-of-bounds read when parsing the crafted data [1].
Impact
Successful exploitation causes a denial of service (DoS) condition on the targeted device [1]. The out-of-bounds read can trigger an unexpected behavior in the COPS processing module, disrupting normal service. The impact is limited to availability; no code execution or information disclosure is indicated in the available references [1].
Mitigation
Huawei has released software updates to address these vulnerabilities [1]. The resolved version for IPS Module V500R001C30 is V500R005C20SPC500; other affected versions should be upgraded to the fixed releases listed in the vendor advisory [1]. Users should apply the available patches as soon as possible. No workarounds are documented.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- Range: V500R001C30
- Range: V500R002C00
- Huawei/NIP6800v5Range: V500R001C60
- Range: V500R001C30
- Range: V500R001C30
- Range: V500R001C30
- Huawei/USG6000Vv5Range: V500R003C00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.