CVE Vulnerabilities

CVE-2020-9114

Improper Privilege Management

Published: Dec 01, 2020 | Modified: Dec 02, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Fusioncompute Huawei 6.3.0 (including) 6.3.0 (including)
Fusioncompute Huawei 6.3.1 (including) 6.3.1 (including)
Fusioncompute Huawei 6.5.0 (including) 6.5.0 (including)
Fusioncompute Huawei 6.5.1 (including) 6.5.1 (including)
Fusioncompute Huawei 8.0.0 (including) 8.0.0 (including)

Potential Mitigations

References