CVE Vulnerabilities

CVE-2020-1861

Published: Feb 28, 2020 | Modified: Jul 21, 2021
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage.

Affected Software

Name Vendor Start Version End Version
Cloudengine_12800_firmware Huawei v200r001c00spc600 (including) v200r001c00spc600 (including)
Cloudengine_12800_firmware Huawei v200r001c00spc700 (including) v200r001c00spc700 (including)
Cloudengine_12800_firmware Huawei v200r002c01 (including) v200r002c01 (including)
Cloudengine_12800_firmware Huawei v200r002c50spc800 (including) v200r002c50spc800 (including)
Cloudengine_12800_firmware Huawei v200r002c50spc800pwe (including) v200r002c50spc800pwe (including)
Cloudengine_12800_firmware Huawei v200r003c00spc810 (including) v200r003c00spc810 (including)
Cloudengine_12800_firmware Huawei v200r003c00spc810pwe (including) v200r003c00spc810pwe (including)
Cloudengine_12800_firmware Huawei v200r005c00spc600 (including) v200r005c00spc600 (including)
Cloudengine_12800_firmware Huawei v200r005c00spc800 (including) v200r005c00spc800 (including)
Cloudengine_12800_firmware Huawei v200r005c00spc800pwe (including) v200r005c00spc800pwe (including)
Cloudengine_12800_firmware Huawei v200r005c10 (including) v200r005c10 (including)
Cloudengine_12800_firmware Huawei v200r005c10spc300 (including) v200r005c10spc300 (including)

References