Information Leakage Vulnerability in Huawei NGFW Module and Secospace Firewalls
CVE-2020-1856

7.5HIGH

Key Information:

Summary

Huawei's NGFW Module and Secospace Firewalls have a vulnerability that allows unauthorized access to sensitive information. Attackers can exploit this flaw by crafting specific request packets, potentially leading to severe information disclosure. Organizations utilizing these devices should apply the relevant security patches and monitor their network traffic for any suspicious activity.

Affected Version(s)

NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R001C30

NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R001C60

NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, USG9500 V500R005C00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.