First published: Tue Dec 29 2020(Updated: )
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by crafting malicious files to bypass current verification mechanism. This can compromise normal service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 5800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r005c20spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9207 is an improper authentication vulnerability in certain versions of Huawei CloudEngine products.
Attackers can exploit CVE-2020-9207 by crafting malicious files to bypass the current verification mechanism.
Certain versions of Huawei CloudEngine 12800, 5800, 6800, and 7800 are affected by CVE-2020-9207.
The severity of CVE-2020-9207 is high with a CVSS score of 7.8.
To fix CVE-2020-9207, it is recommended to apply the latest patches and updates provided by Huawei.