Lucene search

K
cveHuaweiCVE-2020-1860
HistoryFeb 28, 2020 - 7:15 p.m.

CVE-2020-1860

2020-02-2819:15:11
huawei
web.nvd.nist.gov
93
nip6800
secospace usg6600
usg9500
v500r001c30
v500r001c60spc500
v500r005c00spc100
access control bypass
vulnerability
internet access

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.9%

NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be bypassed, and attackers can directly access the Internet.

Affected configurations

Nvd
Vulners
Node
huaweinip6800_firmwareMatchv500r001c30
OR
huaweinip6800_firmwareMatchv500r001c60
OR
huaweinip6800_firmwareMatchv500r005c00
AND
huaweinip6800Match-
Node
huaweisecospace_usg6600_firmwareMatchv500r001c30
OR
huaweisecospace_usg6600_firmwareMatchv500r001c60
OR
huaweisecospace_usg6600_firmwareMatchv500r005c00
AND
huaweisecospace_usg6600Match-
Node
huaweiusg9500_firmwareMatchv500r001c30
OR
huaweiusg9500_firmwareMatchv500r001c60
OR
huaweiusg9500_firmwareMatchv500r005c00
AND
huaweiusg9500Match-
VendorProductVersionCPE
huaweinip6800_firmwarev500r001c30cpe:2.3:o:huawei:nip6800_firmware:v500r001c30:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r001c60cpe:2.3:o:huawei:nip6800_firmware:v500r001c60:*:*:*:*:*:*:*
huaweinip6800_firmwarev500r005c00cpe:2.3:o:huawei:nip6800_firmware:v500r005c00:*:*:*:*:*:*:*
huaweinip6800-cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev500r001c30cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c30:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev500r001c60cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r001c60:*:*:*:*:*:*:*
huaweisecospace_usg6600_firmwarev500r005c00cpe:2.3:o:huawei:secospace_usg6600_firmware:v500r005c00:*:*:*:*:*:*:*
huaweisecospace_usg6600-cpe:2.3:h:huawei:secospace_usg6600:-:*:*:*:*:*:*:*
huaweiusg9500_firmwarev500r001c30cpe:2.3:o:huawei:usg9500_firmware:v500r001c30:*:*:*:*:*:*:*
huaweiusg9500_firmwarev500r001c60cpe:2.3:o:huawei:usg9500_firmware:v500r001c60:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "NIP6800;Secospace USG6600;USG9500",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "V500R001C30,V500R001C60,V500R005C00"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.5

Confidence

High

EPSS

0.001

Percentile

35.9%

Related for CVE-2020-1860