Vulnerabilities (CVE)

Filtered by vendor Huawei Subscribe
Filtered by product Taurus-al00a Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9093 1 Huawei 2 Taurus-al00a, Taurus-al00a Firmware 2020-12-30 4.3 MEDIUM 5.5 MEDIUM
There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which makes a function refer to memory after it has been freed. Attackers can exploit this vulnerability by running a crafted application with common privilege. This would compromise normal service.
CVE-2020-9087 1 Huawei 2 Taurus-al00a, Taurus-al00a Firmware 2020-10-16 2.1 LOW 5.5 MEDIUM
Taurus-AL00A version 10.0.0.1(C00E1R1P1) has an out-of-bounds read vulnerability in XFRM module. An authenticated, local attacker may perform a specific operation to exploit this vulnerability. Due to insufficient validation of the parameters, which may be exploited to cause information leak.