First published: Mon Oct 19 2020(Updated: )
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a privilege elevation vulnerability. Due to lack of privilege restrictions on some of the business functions of the device. An attacker could exploit this vulnerability to access the protecting information, resulting in the elevation of the privilege.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus ncmdump | <10.1.0.156\(c00e155r7p2\) | |
Huawei Taurus ncmdump |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9112 is classified as a privilege elevation vulnerability.
To fix CVE-2020-9112, upgrade the Huawei Taurus-AN00B firmware to version 10.1.0.156(C00E155R7P2) or later.
An attacker can exploit CVE-2020-9112 to access protected information and elevate their privileges on the device.
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) are affected by CVE-2020-9112.
Yes, Huawei has issued a security advisory regarding CVE-2020-9112.