Improper Authorization in Huawei FusionCompute 8.0.0
CVE-2020-9248

6.7MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
31 July 2020

Summary

Huawei FusionCompute 8.0.0 contains an improper authorization vulnerability that allows unauthorized access to resources. The affected module fails to validate input correctly, leading to potential privilege escalation opportunities for malicious actors. By exploiting this flaw, attackers may gain unauthorized file access, compromising the integrity and availability of services within the system.

Affected Version(s)

FusionCompute 8.0.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.