Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9075


Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful exploitation of this vulnerability may lead to information leakage.


Published

2020-06-15T15:15:09.710

Last Modified

2024-11-21T05:39:58.900

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei secospace_usg6300_firmware v500r005c00 Yes
Operating System huawei secospace_usg6300_firmware v500r005c10 Yes
Operating System huawei secospace_usg6600_firmware v500r001c30 Yes
Operating System huawei secospace_usg6600_firmware v500r001c50 Yes
Operating System huawei secospace_usg6600_firmware v500r001c60 Yes
Operating System huawei secospace_usg6600_firmware v500r001c80 Yes
Hardware huawei secospace_usg6300 - No
Operating System huawei usg6300e_firmware v600r006c00 Yes
Hardware huawei usg6300e - No

References