First published: Fri Feb 28 2020(Updated: )
CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r001c00spc600 | |
Huawei Cloudengine 12800 Firmware | =v200r001c00spc700 | |
Huawei Cloudengine 12800 Firmware | =v200r002c01 | |
Huawei Cloudengine 12800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r002c50spc800pwe | |
Huawei Cloudengine 12800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 12800 Firmware | =v200r003c00spc810pwe | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc600 | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc800pwe | |
Huawei Cloudengine 12800 Firmware | =v200r005c10 | |
Huawei Cloudengine 12800 Firmware | =v200r005c10spc300 | |
Huawei CloudEngine 12800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-1861.
The severity level of CVE-2020-1861 is medium with a CVSS score of 4.4.
The CloudEngine 12800 with the following firmware versions: V200R001C00SPC600, V200R001C00SPC700, V200R002C01, V200R002C50SPC800, V200R002C50SPC800PWE, V200R003C00SPC810, V200R003C00SPC810PWE, V200R005C00SPC600, V200R005C00SPC800, V200R005C00SPC800PWE, V200R005C10, V200R005C10SPC300 are affected by CVE-2020-1861.
CloudEngine 12800 with specific firmware versions have an information leakage vulnerability.
Yes, Huawei has released a security advisory containing the fix for CVE-2020-1861. Please refer to the Huawei website for more information.