CVE Vulnerabilities

CVE-2020-9102

Published: Jul 17, 2020 | Modified: Jul 21, 2021
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

There is a information leak vulnerability in some Huawei products, and it could allow a local attacker to get information. The vulnerability is due to the improper management of the username. An attacker with the ability to access the device and cause the username information leak. Affected product versions include: CloudEngine 12800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800; CloudEngine 5800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800; CloudEngine 6800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R005C20SPC800, V200R019C00SPC800; CloudEngine 7800 versions V200R002C50SPC800, V200R003C00SPC810, V200R005C00SPC800, V200R005C10SPC800, V200R019C00SPC800

Affected Software

Name Vendor Start Version End Version
Cloudengine_12800_firmware Huawei v200r002c50spc800 (including) v200r002c50spc800 (including)
Cloudengine_12800_firmware Huawei v200r003c00spc810 (including) v200r003c00spc810 (including)
Cloudengine_12800_firmware Huawei v200r005c00spc800 (including) v200r005c00spc800 (including)
Cloudengine_12800_firmware Huawei v200r005c10spc800 (including) v200r005c10spc800 (including)
Cloudengine_12800_firmware Huawei v200r019c00spc800 (including) v200r019c00spc800 (including)

References