CVE Vulnerabilities

CVE-2020-9068

Improper Authentication

Published: Apr 27, 2020 | Modified: Apr 30, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ar3200_firmware Huawei v200r007c00spc900 (including) v200r007c00spc900 (including)
Ar3200_firmware Huawei v200r007c00spca00 (including) v200r007c00spca00 (including)
Ar3200_firmware Huawei v200r007c00spcb00 (including) v200r007c00spcb00 (including)
Ar3200_firmware Huawei v200r007c00spcc00 (including) v200r007c00spcc00 (including)
Ar3200_firmware Huawei v200r009c00spc500 (including) v200r009c00spc500 (including)

Potential Mitigations

References