CVE-2020-1879: Low severity Huawei Hege-560 Firmware vulnerability
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions 1.0.1.22(SP3);OSCA-550 versions 1.0.1.21(SP3);OSCA-550A versions 1.0.1.21(SP3);OSCA-550AX versions 1.0.1.21(SP3);OSCA-550X versions 1.0.1.21(SP3).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HEGE-560to a version that resolves this vulnerability.Fixed in 1.0.1.21(SP3) - Upgrade
Upgrade
HEGE-570to a version that resolves this vulnerability.Fixed in 1.0.1.22(SP3) - Upgrade
Upgrade
OSCA-550to a version that resolves this vulnerability.Fixed in 1.0.1.21(SP3) - Upgrade
Upgrade
OSCA-550Ato a version that resolves this vulnerability.Fixed in 1.0.1.21(SP3) - Upgrade
Upgrade
OSCA-550AXto a version that resolves this vulnerability.Fixed in 1.0.1.21(SP3) - Upgrade
Upgrade
OSCA-550Xto a version that resolves this vulnerability.Fixed in 1.0.1.21(SP3)
Event History
Frequently Asked Questions
What is CVE-2020-1879?
CVE-2020-1879 is an improper integrity checking vulnerability on some Huawei products.
Which Huawei products are affected by CVE-2020-1879?
The affected Huawei products include HEGE-560 versions 1.0.1.21(SP3), HEGE-570 versions 1.0.1.21(SP3), and Huawei Osca-550 versions 1.0.1.21(SP3).
What is the severity of CVE-2020-1879?
The severity of CVE-2020-1879 is low with a CVSS score of 3.9.
How can an attacker exploit CVE-2020-1879?
An attacker with high privileges can exploit CVE-2020-1879 to make malicious modifications.
Are there any references for more information on CVE-2020-1879?
Yes, you can find more information on CVE-2020-1879 at the following links: [Huawei Security Advisory 20200415-02](http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-en) and [Huawei Security Advisory 20200311-01](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-integrity-en).