Lucene search

K
cveHuaweiCVE-2020-1879
HistoryMar 20, 2020 - 4:15 p.m.

CVE-2020-1879

2020-03-2016:15:15
CWE-354
huawei
web.nvd.nist.gov
74
cve-2020-1879
huawei
integrity checking
vulnerability
malicious modifications
hege-560
hege-570
osca-550
osca-550a
osca-550ax
osca-550x

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

CVSS3

3.9

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

12.6%

There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions 1.0.1.22(SP3);OSCA-550 versions 1.0.1.21(SP3);OSCA-550A versions 1.0.1.21(SP3);OSCA-550AX versions 1.0.1.21(SP3);OSCA-550X versions 1.0.1.21(SP3).

Affected configurations

Nvd
Vulners
Node
huaweihege-560_firmwareMatch1.0.1.21\(sp3\)
AND
huaweihege-560Match-
Node
huaweihege-570_firmwareMatch1.0.1.21\(sp3\)
AND
huaweihege-570Match-
Node
huaweiosca-550_firmwareMatch1.0.1.21\(sp3\)
AND
huaweiosca-550Match-
Node
huaweiosca-550a_firmwareMatch1.0.1.21\(sp3\)
AND
huaweiosca-550aMatch-
Node
huaweiosca-550ax_firmwareMatch1.0.1.21\(sp3\)
AND
huaweiosca-550axMatch-
Node
huaweiosca-550x_firmwareMatch1.0.1.21\(sp3\)
AND
huaweiosca-550xMatch-
VendorProductVersionCPE
huaweihege-560_firmware1.0.1.21(sp3)cpe:2.3:o:huawei:hege-560_firmware:1.0.1.21\(sp3\):*:*:*:*:*:*:*
huaweihege-560-cpe:2.3:h:huawei:hege-560:-:*:*:*:*:*:*:*
huaweihege-570_firmware1.0.1.21(sp3)cpe:2.3:o:huawei:hege-570_firmware:1.0.1.21\(sp3\):*:*:*:*:*:*:*
huaweihege-570-cpe:2.3:h:huawei:hege-570:-:*:*:*:*:*:*:*
huaweiosca-550_firmware1.0.1.21(sp3)cpe:2.3:o:huawei:osca-550_firmware:1.0.1.21\(sp3\):*:*:*:*:*:*:*
huaweiosca-550-cpe:2.3:h:huawei:osca-550:-:*:*:*:*:*:*:*
huaweiosca-550a_firmware1.0.1.21(sp3)cpe:2.3:o:huawei:osca-550a_firmware:1.0.1.21\(sp3\):*:*:*:*:*:*:*
huaweiosca-550a-cpe:2.3:h:huawei:osca-550a:-:*:*:*:*:*:*:*
huaweiosca-550ax_firmware1.0.1.21(sp3)cpe:2.3:o:huawei:osca-550ax_firmware:1.0.1.21\(sp3\):*:*:*:*:*:*:*
huaweiosca-550ax-cpe:2.3:h:huawei:osca-550ax:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CNA Affected

[
  {
    "product": "HEGE-560;HEGE-570;OSCA-550;OSCA-550A;OSCA-550AX;OSCA-550X",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "1.0.1.21(SP3)"
      },
      {
        "status": "affected",
        "version": "1.0.1.22(SP3)"
      }
    ]
  }
]

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

CVSS3

3.9

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

AI Score

4.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2020-1879