There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise normal service.
2020-12-29T18:15:13.337
2024-11-21T05:40:10.117
Modified
CVSSv3.1: 7.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei | cloudengine_12800_firmware | v200r019c00spc800 | Yes |
Hardware | huawei | cloudengine_12800 | - | No |
Operating System | huawei | cloudengine_5800_firmware | v200r019c00spc800 | Yes |
Hardware | huawei | cloudengine_5800 | - | No |
Operating System | huawei | cloudengine_6800_firmware | v200r005c20spc800 | Yes |
Operating System | huawei | cloudengine_6800_firmware | v200r019c00spc800 | Yes |
Hardware | huawei | cloudengine_6800 | - | No |
Operating System | huawei | cloudengine_7800_firmware | v200r019c00spc800 | Yes |
Hardware | huawei | cloudengine_7800 | - | No |