CVE-2020-9127
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospace USG6300 versions V500R001C30,V500R001C60;Secospace USG6500 versions V500R001C30,V500R001C60;Secospace USG6600 versions V500R001C30,V500R001C60;USG9500 versions V500R001C30,V500R001C60.
Affected (12)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Nip6300 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Nip6600 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6300 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6500 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Secospace Usg6600 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c30 |
| Running on/with | Platform Versions |
|---|---|
Huawei Usg9500 | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.