CSV Injection Vulnerability in iManager NetEco 6000 from Huawei
CVE-2020-9200
7.8HIGH
Summary
A vulnerability has been identified in the iManager NetEco 6000, specifically in version V600R021C00, which allows attackers with basic privileges to exploit insufficient input validation on parameters. By leveraging this flaw, attackers can inject malicious CSV files into the target device, potentially leading to unauthorized data manipulation or information disclosure.
Affected Version(s)
iManager NetEco 6000 V600R021C00
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved