CVE Vulnerabilities

CVE-2020-9068

Improper Authentication

Published: Apr 27, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Ar3200_firmwareHuaweiv200r007c00spc900 (including)v200r007c00spc900 (including)
Ar3200_firmwareHuaweiv200r007c00spca00 (including)v200r007c00spca00 (including)
Ar3200_firmwareHuaweiv200r007c00spcb00 (including)v200r007c00spcb00 (including)
Ar3200_firmwareHuaweiv200r007c00spcc00 (including)v200r007c00spcc00 (including)
Ar3200_firmwareHuaweiv200r009c00spc500 (including)v200r009c00spc500 (including)

Potential Mitigations

References