CVE-2020-1842: Medium severity Huawei Hege-560 Firmware vulnerability
Published Feb 18, 2020
·Updated
Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker obtain high privilege.
Affected Software
20 affected components
Huawei Hege-560 Firmware=1.0.1.20\(sp2\)
Huawei HEGE-560
Huawei Osca-550 Firmware=1.0.0.71\(sp1\)
Huawei OSCA-550
Huawei Osca-550a Firmware=1.0.0.71\(sp1\)
Huawei OSCA-550A
Huawei Osca-550ax Firmware=1.0.0.71\(sp2\)
Huawei OSCA-550AX
Huawei Osca-550x Firmware=1.0.0.71\(sp2\)
Huawei OSCA-550X
All of the following
Huawei Hege-560 Firmware=1.0.1.20\(sp2\)
Huawei HEGE-560
All of the following
Huawei Osca-550 Firmware=1.0.0.71\(sp1\)
Huawei OSCA-550
All of the following
Huawei Osca-550a Firmware=1.0.0.71\(sp1\)
Huawei OSCA-550A
All of the following
Huawei Osca-550ax Firmware=1.0.0.71\(sp2\)
Huawei OSCA-550AX
All of the following
Huawei Osca-550x Firmware=1.0.0.71\(sp2\)
Huawei OSCA-550X
Event History
Feb 18, 2020
CVE Published
via MITRE·03:03 AM
Data Sourced
via MITRE·03:03 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-1842.
2
What is the severity of CVE-2020-1842?
The severity of CVE-2020-1842 is medium.
3
How does the vulnerability affect Huawei HEGE-560 devices?
Huawei HEGE-560 devices are affected by this vulnerability.
4
What is the fix for CVE-2020-1842?
There is currently no fixed version available for CVE-2020-1842. Please refer to the vendor's advisory for more information.
5
Where can I find more information about CVE-2020-1842?
You can find more information about CVE-2020-1842 in Huawei's security advisory.