First published: Tue Feb 18 2020(Updated: )
Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) have an insufficient authentication vulnerability. The software does not require a strong credential when the user trying to do certain operations. Successful exploit could allow an attacker to pass the authentication and do certain operations by a weak credential.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Osca-550 Firmware | =1.0.1.21\(sp3\) | |
Huawei OSCA-550 | ||
Huawei Osca-550a Firmware | =1.0.1.21\(sp3\) | |
Huawei Osca-550a | ||
Huawei Osca-550ax Firmware | =1.0.1.21\(sp3\) | |
Huawei Osca-550ax | ||
Huawei Osca-550x Firmware | =1.0.1.21\(sp3\) | |
Huawei Osca-550x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1789 is a vulnerability in Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3) where the software has an insufficient authentication vulnerability.
An attacker can exploit CVE-2020-1789 by taking advantage of the insufficient authentication vulnerability in Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products with version 1.0.1.21(SP3).
CVE-2020-1789 has a severity rating of 6.8, which is medium.
To fix CVE-2020-1789, it is recommended to update the affected Huawei OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X products to version 1.0.1.21(SP3) or later.
More information about CVE-2020-1789 can be found on the Huawei Security Advisory page: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200121-01-osca-en.