CVE Vulnerabilities

CVE-2020-1861

Published: Feb 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage.

Affected Software

NameVendorStart VersionEnd Version
Cloudengine_12800_firmwareHuaweiv200r001c00spc600 (including)v200r001c00spc600 (including)
Cloudengine_12800_firmwareHuaweiv200r001c00spc700 (including)v200r001c00spc700 (including)
Cloudengine_12800_firmwareHuaweiv200r002c01 (including)v200r002c01 (including)
Cloudengine_12800_firmwareHuaweiv200r002c50spc800 (including)v200r002c50spc800 (including)
Cloudengine_12800_firmwareHuaweiv200r002c50spc800pwe (including)v200r002c50spc800pwe (including)
Cloudengine_12800_firmwareHuaweiv200r003c00spc810 (including)v200r003c00spc810 (including)
Cloudengine_12800_firmwareHuaweiv200r003c00spc810pwe (including)v200r003c00spc810pwe (including)
Cloudengine_12800_firmwareHuaweiv200r005c00spc600 (including)v200r005c00spc600 (including)
Cloudengine_12800_firmwareHuaweiv200r005c00spc800 (including)v200r005c00spc800 (including)
Cloudengine_12800_firmwareHuaweiv200r005c00spc800pwe (including)v200r005c00spc800pwe (including)
Cloudengine_12800_firmwareHuaweiv200r005c10 (including)v200r005c10 (including)
Cloudengine_12800_firmwareHuaweiv200r005c10spc300 (including)v200r005c10spc300 (including)

References