First published: Fri Dec 27 2024(Updated: )
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Fusioncompute Firmware | =6.3.0 | |
Huawei Fusioncompute Firmware | =6.3.1 | |
Huawei Fusioncompute Firmware | =6.5.0 | |
Huawei Fusioncompute Firmware | =6.5.1 | |
Huawei Fusioncompute Firmware | =8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9222 has been rated as a high-severity vulnerability due to its potential for privilege escalation.
To fix CVE-2020-9222, users should update Huawei FusionCompute to the latest fixed versions provided by Huawei.
CVE-2020-9222 affects Huawei FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1, and 8.0.0.
CVE-2020-9222 can be exploited by local attackers with access to the system.
CVE-2020-9222 is a privilege escalation vulnerability that allows users to elevate permissions.