CVE Vulnerabilities

CVE-2020-9114

Improper Privilege Management

Published: Dec 01, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
FusioncomputeHuawei6.3.0 (including)6.3.0 (including)
FusioncomputeHuawei6.3.1 (including)6.3.1 (including)
FusioncomputeHuawei6.5.0 (including)6.5.0 (including)
FusioncomputeHuawei6.5.1 (including)6.5.1 (including)
FusioncomputeHuawei8.0.0 (including)8.0.0 (including)

Potential Mitigations

References