Information Leakage Vulnerability in Huawei NGFW Module and Secospace Firewalls
CVE-2020-1856
7.5HIGH
Key Information:
- Vendor
- Huawei
- Vendor
- CVE Published:
- 17 February 2020
Summary
Huawei's NGFW Module and Secospace Firewalls have a vulnerability that allows unauthorized access to sensitive information. Attackers can exploit this flaw by crafting specific request packets, potentially leading to severe information disclosure. Organizations utilizing these devices should apply the relevant security patches and monitor their network traffic for any suspicious activity.
Affected Version(s)
NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R001C30
NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R001C60
NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R005C00
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved