cbcvebase.
CVE-2020-9099
published 2020-06-08

CVE-2020-9099: Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
54.8th percentile
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.

Affected

80 ranges· showing 25
VendorProductVersion rangeFixed in
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweinip6300_firmware
huaweinip6300_firmware
huaweinip6300_firmware
huaweinip6300_firmware

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.