First published: Mon Jun 08 2020(Updated: )
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Successful exploit may obtain certain permissions on the device.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei IPS firmware | =v500r001c00 | |
Huawei IPS firmware | =v500r001c20 | |
Huawei IPS firmware | =v500r001c30 | |
Huawei IPS firmware | =v500r001c50 | |
Huawei IPS firmware | =v500r001c60 | |
Huawei IPS firmware | =v500r001c80 | |
Huawei IPS firmware | =v500r005c00 | |
Huawei IPS firmware | =v500r005c10 | |
Huawei IPS firmware | =v500r005c20 | |
Huawei IPS Module firmware | ||
Huawei NGFW Module firmware | =v500r001c00 | |
Huawei NGFW Module firmware | =v500r001c20 | |
Huawei NGFW Module firmware | =v500r001c30 | |
Huawei NGFW Module firmware | =v500r001c50 | |
Huawei NGFW Module firmware | =v500r001c60 | |
Huawei NGFW Module firmware | =v500r002c00 | |
Huawei NGFW Module firmware | =v500r002c10 | |
Huawei NGFW Module firmware | =v500r002c20 | |
Huawei NGFW Module firmware | =v500r002c30 | |
Huawei NGFW Module firmware | =v500r005c00 | |
Huawei NGFW Module firmware | =v500r005c10 | |
Huawei NGFW Module firmware | =v500r005c20 | |
Huawei NGFW Module | ||
Huawei NIP6300 firmware | =v500r001c00 | |
Huawei NIP6300 firmware | =v500r001c20 | |
Huawei NIP6300 firmware | =v500r001c30 | |
Huawei NIP6300 firmware | =v500r001c50 | |
Huawei NIP6300 firmware | =v500r001c60 | |
Huawei NIP6300 firmware | =v500r001c80 | |
Huawei NIP6300 firmware | =v500r005c00 | |
Huawei NIP6300 firmware | =v500r005c10 | |
Huawei NIP6300 firmware | =v500r005c20 | |
Huawei NIP6300 firmware | ||
Huawei NIP6600 | =v500r001c00 | |
Huawei NIP6600 | =v500r001c20 | |
Huawei NIP6600 | =v500r001c30 | |
Huawei NIP6600 | =v500r001c50 | |
Huawei NIP6600 | =v500r001c60 | |
Huawei NIP6600 | =v500r001c80 | |
Huawei NIP6600 | =v500r005c00 | |
Huawei NIP6600 | =v500r005c10 | |
Huawei NIP6600 | =v500r005c20 | |
Huawei NIP6600 firmware | ||
Huawei NIP6800 Firmware | =v500r001c60 | |
Huawei NIP6800 Firmware | =v500r001c80 | |
Huawei NIP6800 Firmware | =v500r005c00 | |
Huawei NIP6800 Firmware | =v500r005c10 | |
Huawei NIP6800 Firmware | =v500r005c20 | |
Huawei NIP6800 Firmware | ||
Huawei USG6300E firmware | =v500r001c00 | |
Huawei USG6300E firmware | =v500r001c20 | |
Huawei USG6300E firmware | =v500r001c30 | |
Huawei USG6300E firmware | =v500r001c50 | |
Huawei USG6300E firmware | =v500r001c60 | |
Huawei USG6300E firmware | =v500r001c80 | |
Huawei USG6300E firmware | =v500r005c00 | |
Huawei USG6300E firmware | =v500r005c10 | |
Huawei USG6300E firmware | =v500r005c20 | |
Huawei Secospace USG6300 firmware | ||
Huawei Secospace USG6500 | =v500r001c00 | |
Huawei Secospace USG6500 | =v500r001c20 | |
Huawei Secospace USG6500 | =v500r001c30 | |
Huawei Secospace USG6500 | =v500r001c50 | |
Huawei Secospace USG6500 | =v500r001c60 | |
Huawei Secospace USG6500 | =v500r001c80 | |
Huawei Secospace USG6500 | =v500r005c00 | |
Huawei Secospace USG6500 | =v500r005c10 | |
Huawei Secospace USG6500 | =v500r005c20 | |
Huawei Secospace USG6500 firmware | ||
Huawei Secospace USG6600 firmware | =v500r001c00 | |
Huawei Secospace USG6600 firmware | =v500r001c20 | |
Huawei Secospace USG6600 firmware | =v500r001c30 | |
Huawei Secospace USG6600 firmware | =v500r001c50 | |
Huawei Secospace USG6600 firmware | =v500r001c60 | |
Huawei Secospace USG6600 firmware | =v500r001c80 | |
Huawei Secospace USG6600 firmware | =v500r005c00 | |
Huawei Secospace USG6600 firmware | =v500r005c10 | |
Huawei Secospace USG6600 firmware | =v500r005c20 | |
Huawei Secospace USG6600 firmware | ||
Huawei USG9500 firmware | =v500r001c00 | |
Huawei USG9500 firmware | =v500r001c20 | |
Huawei USG9500 firmware | =v500r001c30 | |
Huawei USG9500 firmware | =v500r001c50 | |
Huawei USG9500 firmware | =v500r001c60 | |
Huawei USG9500 firmware | =v500r001c80 | |
Huawei USG9500 firmware | =v500r005c00 | |
Huawei USG9500 firmware | =v500r005c10 | |
Huawei USG9500 firmware | =v500r005c20 | |
Huawei Eudemon USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9099 has a high severity rating due to its potential for exploitation in Huawei products.
To remediate CVE-2020-9099, upgrade affected Huawei products to the latest firmware version as recommended by Huawei.
CVE-2020-9099 affects various Huawei devices including IPS Module, NGFW Module, NIP6300, NIP6600, NIP6800, and Secospace USG Series.
Currently, there are no known workarounds for CVE-2020-9099; updating firmware is the only recommended action.
CVE-2020-9099 was disclosed by Huawei on May 6, 2020.