Command Injection Vulnerability in Huawei Networking Products
CVE-2020-9127

6.7MEDIUM

Key Information:

Summary

A command injection vulnerability exists in multiple Huawei networking products due to insufficient input validation. This flaw allows a high-privileged attacker to inject malicious commands into specific files, potentially leading to unauthorized access and manipulation of the affected devices. Various models, including the NIP6300, NIP6600, and the Secospace USG series, are affected by this issue, emphasizing the need for immediate patching to mitigate security risks.

Affected Version(s)

NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 V500R001C30,V500R001C60

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.