CVE-2020-1822
Description
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple out-of-bounds read vulnerabilities in Huawei COPS protocol implementation can cause denial of service via crafted packets.
Vulnerability
The Common Open Policy Service (COPS) protocol implementation in certain Huawei products contains multiple out-of-bounds (OOB) read vulnerabilities. The specific decoding function performs an OOB read when processing a crafted incoming data packet. Affected products include the IPS Module in versions V500R001C30, V500R001C60, V500R005C00, and other versions listed in the advisory [1]. These vulnerabilities are tracked as CVE-2020-1818 through CVE-2020-1824, with CVE-2020-1822 being one of them.
Exploitation
An attacker can exploit these vulnerabilities by sending a specially crafted COPS packet to an affected device. No authentication is required if the COPS service is exposed to the network. The attacker only needs network access to deliver the malicious packet. The OOB read occurs during packet decoding, which can lead to a crash or service disruption.
Impact
Successful exploitation results in denial of service (DoS) due to disruption of the affected device's service. The OOB read may cause the device to become unresponsive or restart, impacting availability. There is no indication of code execution or information disclosure beyond the out-of-bounds memory read.
Mitigation
Huawei has released software updates to fix these vulnerabilities. For the IPS Module, the resolved version is V500R005C20SPC500. Users should upgrade to the fixed version as listed in the security advisory [1]. No workarounds are provided. The advisory was published in 2020, and patches are available for all affected versions.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- Range: V500R001C30
- Range: V500R002C00
- Huawei/NIP6800v5Range: V500R001C60
- Range: V500R001C30
- Range: V500R001C30
- Range: V500R001C30
- Huawei/USG6000Vv5Range: V500R003C00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.