CVE Vulnerabilities

CVE-2020-9222

Improper Privilege Management

Published: Dec 27, 2024 | Modified: Jan 15, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Fusioncompute Huawei 6.3.0 (including) 6.3.0 (including)
Fusioncompute Huawei 6.3.1 (including) 6.3.1 (including)
Fusioncompute Huawei 6.5.0 (including) 6.5.0 (including)
Fusioncompute Huawei 6.5.1 (including) 6.5.1 (including)
Fusioncompute Huawei 8.0.0 (including) 8.0.0 (including)

Potential Mitigations

References