There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause out-of-bounds read and write.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: huawei
Published: 2022-09-20T19:42:39.000Z
Updated: 2025-05-28T16:04:39.495Z
Reserved: 2022-08-25T00:00:00.000Z
Link: CVE-2020-36602
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T17:30:08.396Z
 NVD
                        NVD
                    Status : Modified
Published: 2022-09-20T20:15:09.723
Modified: 2025-05-28T16:15:21.060
Link: CVE-2020-36602
 Redhat
                        Redhat
                    No data.