VYPR
Unrated severityNVD Advisory· Published Dec 28, 2024· Updated Dec 30, 2024

CVE-2020-1821

CVE-2020-1821

Description

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)

The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple OOB read vulnerabilities in the COPS protocol implementation of some Huawei products can be exploited to disrupt device service.

Vulnerability

Multiple out-of-bounds (OOB) read vulnerabilities exist in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function performs an out-of-bounds read when processing an incoming data packet. Affected products and versions include IPS Module V500R001C30, V500R001C60, V500R005C00, and others as listed in the advisory [1].

Exploitation

An attacker must send a crafted COPS data packet to the affected device. No authentication or special network position beyond the ability to deliver a malformed packet to the COPS decoding function is required [1].

Impact

Successful exploitation causes a denial of service by disrupting service on the affected device [1].

Mitigation

Huawei has released software updates to fix these vulnerabilities. For IPS Module, the resolved version is V500R005C20SPC500. Users should upgrade to the fixed versions as indicated in the security advisory [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

10

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.