First published: Thu Dec 24 2020(Updated: )
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 5800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 5800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 6800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c20spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c10spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 7800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r019c10spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9137 is a privilege escalation vulnerability in some versions of CloudEngine 12800, CloudEngine 5800, CloudEngine 6800, and CloudEngine 7800.
CVE-2020-9137 allows a local attacker with high privilege to execute specially crafted scripts in the affected products, leading to privilege escalation.
The severity of CVE-2020-9137 is medium, with a CVSS score of 6.7.
Versions v200r002c50spc800, v200r003c00spc810, v200r005c00spc800, v200r005c10spc800, v200r019c00spc800, and v200r019c10spc800 of Huawei CloudEngine firmware are affected by CVE-2020-9137.
You can find more information about CVE-2020-9137 in the security advisory published by Huawei at https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201202-02-privilege-en.