CVE Vulnerabilities

CVE-2020-1871

Published: Jan 03, 2020 | Modified: Jul 21, 2021
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C00SPC200 have an improper credentials management vulnerability. The software does not properly manage certain credentials. Successful exploit could cause information disclosure or damage, and impact the confidentiality or integrity.

Affected Software

Name Vendor Start Version End Version
Usg9500_firmware Huawei v500r001c30spc100 (including) v500r001c30spc100 (including)
Usg9500_firmware Huawei v500r001c30spc200 (including) v500r001c30spc200 (including)
Usg9500_firmware Huawei v500r001c30spc600 (including) v500r001c30spc600 (including)
Usg9500_firmware Huawei v500r001c60spc500 (including) v500r001c60spc500 (including)
Usg9500_firmware Huawei v500r005c00spc100 (including) v500r005c00spc100 (including)
Usg9500_firmware Huawei v500r005c00spc200 (including) v500r005c00spc200 (including)

References