CVE-2020-9207

Severity
7.8HIGH
EPSS
0.1%
top 75.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 29
Latest updateMay 24

Description

There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise normal service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

CVEListV5huawei/cloudengine_5800V200R019C00SPC800
CVEListV5huawei/cloudengine_6800V200R005C20SPC800, V200R019C00SPC800+1
CVEListV5huawei/cloudengine_7800V200R019C00SPC800
CVEListV5huawei/cloudengine_12800V200R019C00SPC800
NVDhuawei/cloudengine_5800_firmwarev200r019c00spc800

🔴Vulnerability Details

2
GHSA
GHSA-g8q3-q7hj-qv33: There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product2022-05-24
CVEList
CVE-2020-9207: There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product2020-12-29