6.8
CVE-2020-1842
- EPSS 0.24%
- Veröffentlicht 18.02.2020 04:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:28
- Erkennungen
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker obtain high privilege.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Hege-560 Firmware Version 1.0.1.20(sp2)
Huawei ≫ Osca-550 Firmware Version 1.0.0.71(sp1)
Huawei ≫ Osca-550a Firmware Version 1.0.0.71(sp1)
Huawei ≫ Osca-550ax Firmware Version 1.0.0.71(sp2)
Huawei ≫ Osca-550x Firmware Version 1.0.0.71(sp2)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.143 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-osca-en