VYPR
Unrated severityNVD Advisory· Published Dec 28, 2024· Updated Dec 28, 2024

CVE-2020-1824

CVE-2020-1824

Description

There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)

The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple out-of-bounds read vulnerabilities in the COPS implementation of some Huawei products could cause service disruption.

Vulnerability

Multiple out-of-bounds (OOB) read vulnerabilities exist in the Common Open Policy Service (COPS) protocol implementation of certain Huawei products, including the IPS Module. The flaw resides in a specific decoding function that fails to properly validate input, leading to an OOB read when processing a crafted data packet. Affected versions include V500R001C30, V500R001C60, and V500R005C00 among others. These vulnerabilities are tracked as seven CVEs (CVE-2020-1818 through CVE-2020-1824) and multiple Huawei PSIRT IDs [1].

Exploitation

An attacker can exploit these vulnerabilities by sending a specially crafted COPS packet to an affected device over the network. No authentication is required, making the attack remotely exploitable. The attacker does not need any prior access or privileges, only network connectivity to the target device [1].

Impact

Successful exploitation results in an out-of-bounds read, which can cause the affected device's service to become disrupted. The impact is a denial of service (DoS) condition, potentially affecting the availability of the device. There is no indication of code execution or data compromise [1].

Mitigation

Huawei has released software updates to fix these vulnerabilities. For the IPS Module, the resolved version is V500R005C20SPC500. Other affected products have corresponding fixed versions detailed in the advisory. Users are advised to upgrade to the latest firmware versions. No workarounds are documented. The advisory is available at [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

9

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.