Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200716-01-DNS
HistoryJul 16, 2020 - 12:00 a.m.

Security Advisory - Windows DNS Server Remote Code Execution Vulnerability

2020-07-1600:00:00
Huawei Technologies
www.huawei.com
54

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.944

Percentile

99.3%

Microsoft’s security update in July 2020 addresses the CVE-2020-1350 vulnerability. To exploit the vulnerability, an unauthenticated attacker could send specially crafted requests to a Windows DNS server. An attacker who successfully exploited the vulnerability could run arbitrary code remotely. (Vulnerability ID: HWPSIRT-2020-59863)

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200716-01-dns-en

Affected configurations

Vulners
Node
huaweiagile_controller-campus_firmwareMatchv100r002c00
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc100
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc101
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc102
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc103
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc105
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc106
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc107
OR
huaweiagile_controller-campus_firmwareMatchv100r002c00spc200
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc100
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc101
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc200
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc300
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc400
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc401
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc402
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc403
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc404
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc405
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc406
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc407
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc408
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc409
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc410
OR
huaweiagile_controller-campus_firmwareMatchv100r002c10spc411
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc100
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc101
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc102
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc103
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc105
OR
huaweiagile_controller-campus_firmwareMatchv100r003c30spc106
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc100
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc200
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc300
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc301
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc302
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc303
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc305
OR
huaweiagile_controller-campus_firmwareMatchv100r003c50spc306
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc100
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc200
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc201
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc202
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc203
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc205
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc206
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc207
OR
huaweiagile_controller-campus_firmwareMatchv100r003c60spc208
VendorProductVersionCPE
huaweiagile_controller-campus_firmwarev100r002c00cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc100cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc100:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc101cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc101:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc102cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc102:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc103cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc103:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc105cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc105:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc106cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc106:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc107cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc107:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c00spc200cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c00spc200:*:*:*:*:*:*:*
huaweiagile_controller-campus_firmwarev100r002c10cpe:2.3:o:huawei:agile_controller-campus_firmware:v100r002c10:*:*:*:*:*:*:*
Rows per page:
1-10 of 521

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.944

Percentile

99.3%