Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20200930-01-QEMU
HistorySep 30, 2020 - 12:00 a.m.

Security Advisory - QEMU Out-of-bound Read and Write Vulnerability in Huawei Product

2020-09-3000:00:00
Huawei Technologies
www.huawei.com
46
qemu
usb
vulnerability
code execution
dos
huawei
software update

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

30.2%

An out-of-bound read and write access vulnerability was found in the USB emulator of the QEMU. It occurs while processing USB packets from a guest. Attackers can use this vulnerability to crash the QEMU process resulting in DoS or potentially execute arbitrary code with the privileges of the QEMU process on the host. This can compromise normal service of the affected product. (Vulnerability ID: HWPSIRT-2020-61105) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-14364.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-01-qemu-en

Affected configurations

Vulners
Node
huaweifusioncompute_firmwareMatch6.3.0
OR
huaweifusioncompute_firmwareMatch6.3.1
OR
huaweifusioncompute_firmwareMatch6.5.0
OR
huaweifusioncompute_firmwareMatch6.5.1
OR
huaweifusioncompute_firmwareMatch6.5.1.spc1
OR
huaweifusioncompute_firmwareMatch8.0.0.spc1
OR
huaweifusioncompute_firmwareMatch8.0.rc2
OR
huaweifusioncompute_firmwareMatchv100r006c00
OR
huaweifusioncompute_firmwareMatchv100r006c10
OR
huaweifusioncompute_firmwareMatchv100r006c10rc1
OR
huaweifusioncompute_firmwareMatchv100r006c10rc2
OR
huaweifusioncompute_firmwareMatchv100r006c10spc100
OR
huaweifusioncompute_firmwareMatchv100r006c10spc106
OR
huaweifusioncompute_firmwareMatchv100r006c10sph105
OR
huaweifusioncompute_firmwareMatchv100r006c10u10
OR
huaweifusioncompute_firmwareMatchv100r006c10u20
OR
huaweifusioncompute_firmwareMatchv100r007c00
OR
huaweifusionsphere_openstack_firmwareMatch8.0.0
OR
huaweifusionsphere_openstack_firmwareMatch8.0.1
OR
huaweifusionsphereMatch6.5.1.spc23
OR
huaweifusionsphereMatch8.0.0.spc10
OR
huaweioceanstor_5300_firmwareMatchv300r006c00
OR
huaweioceanstor_5300_firmwareMatchv300r006c01
OR
huaweioceanstor_5300_firmwareMatchv300r006c10
OR
huaweioceanstor_5300_firmwareMatchv300r006c20
OR
huaweioceanstor_5300_firmwareMatchv300r006c30
OR
huaweioceanstor_5300_firmwareMatchv300r006c50
OR
huaweioceanstor_5300_firmwareMatchv300r006c60
OR
huaweioceanstor_5500_firmwareMatchv300r006c00
OR
huaweioceanstor_5500_firmwareMatchv300r006c01
OR
huaweioceanstor_5500_firmwareMatchv300r006c10
OR
huaweioceanstor_5500_firmwareMatchv300r006c20
OR
huaweioceanstor_5500_firmwareMatchv300r006c30
OR
huaweioceanstor_5500_firmwareMatchv300r006c50
OR
huaweioceanstor_5500_firmwareMatchv300r006c60
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c00
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c01
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c10
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c20
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c30
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c50
OR
huaweioceanstor_5600_v3_firmwareMatchv300r006c60
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c00
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c01
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c10
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c20
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c30
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c50
OR
huaweioceanstor_5800_v3_firmwareMatchv300r006c60
OR
huaweiecns280_td_firmwareMatchv100r005c00
OR
huaweiecns280_td_firmwareMatchv100r005c10
OR
huaweiese620x_vess_firmwareMatchv100r001c10spc200
OR
huaweiese620x_vess_firmwareMatchv100r001c20spc200
VendorProductVersionCPE
huaweifusioncompute_firmware6.3.0cpe:2.3:o:huawei:fusioncompute_firmware:6.3.0:*:*:*:*:*:*:*
huaweifusioncompute_firmware6.3.1cpe:2.3:o:huawei:fusioncompute_firmware:6.3.1:*:*:*:*:*:*:*
huaweifusioncompute_firmware6.5.0cpe:2.3:o:huawei:fusioncompute_firmware:6.5.0:*:*:*:*:*:*:*
huaweifusioncompute_firmware6.5.1cpe:2.3:o:huawei:fusioncompute_firmware:6.5.1:*:*:*:*:*:*:*
huaweifusioncompute_firmware6.5.1.spc1cpe:2.3:o:huawei:fusioncompute_firmware:6.5.1.spc1:*:*:*:*:*:*:*
huaweifusioncompute_firmware8.0.0.spc1cpe:2.3:o:huawei:fusioncompute_firmware:8.0.0.spc1:*:*:*:*:*:*:*
huaweifusioncompute_firmware8.0.rc2cpe:2.3:o:huawei:fusioncompute_firmware:8.0.rc2:*:*:*:*:*:*:*
huaweifusioncompute_firmwarev100r006c00cpe:2.3:o:huawei:fusioncompute_firmware:v100r006c00:*:*:*:*:*:*:*
huaweifusioncompute_firmwarev100r006c10cpe:2.3:o:huawei:fusioncompute_firmware:v100r006c10:*:*:*:*:*:*:*
huaweifusioncompute_firmwarev100r006c10rc1cpe:2.3:o:huawei:fusioncompute_firmware:v100r006c10rc1:*:*:*:*:*:*:*
Rows per page:
1-10 of 531

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS3

5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

30.2%