9.8
CVE-2020-9068
- EPSS 0.16%
- Published 27.04.2020 16:15:12
- Last modified 21.11.2024 05:39:57
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Ar3200 Firmware Versionv200r007c00spc900
Huawei ≫ Ar3200 Firmware Versionv200r007c00spca00
Huawei ≫ Ar3200 Firmware Versionv200r007c00spcb00
Huawei ≫ Ar3200 Firmware Versionv200r007c00spcc00
Huawei ≫ Ar3200 Firmware Versionv200r009c00spc500
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.336 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.