6.7
CVE-2020-9248
- EPSS 0.23%
- Veröffentlicht 31.07.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:40:16
- Erkennungen
Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly and authorizes files with incorrect access. Attackers can exploit this vulnerability to launch privilege escalation attack. This can compromise normal service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Fusioncompute Version 8.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.131 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-01-fc-en