Improper Authentication Vulnerability in Huawei CloudEngine
CVE-2020-9207

7.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
29 December 2020

Summary

An improper authentication vulnerability exists within certain versions of Huawei's CloudEngine, resulting from a failure to verify input files accurately. This flaw enables attackers to exploit the system by crafting malicious files that can bypass existing verification mechanisms, potentially compromising normal service operations.

Affected Version(s)

CloudEngine 12800 V200R019C00SPC800

CloudEngine 5800 V200R019C00SPC800

CloudEngine 6800 V200R005C20SPC800

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.