← Zuruck zu CVEs
CVE-2020-9099
CRITICAL9.8
Beschreibung
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/8/2020
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
huawei:ips_modulehuawei:ips_module_firmwarehuawei:ngfw_modulehuawei:ngfw_module_firmwarehuawei:nip6300huawei:nip6300_firmwarehuawei:nip6600huawei:nip6600_firmwarehuawei:nip6800huawei:nip6800_firmwarehuawei:secospace_usg6300huawei:secospace_usg6300_firmwarehuawei:secospace_usg6500huawei:secospace_usg6500_firmwarehuawei:secospace_usg6600huawei:secospace_usg6600_firmwarehuawei:usg9500huawei:usg9500_firmware
Schwachen (CWE)
CWE-287
Referenzen
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200506-02-authentication-en(psirt@huawei.com)
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200506-02-authentication-en(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.