CVE-2020-9199
6.8
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.
Affected (3)
Products: Huawei: B2368 22 Firmware, B2368 57 Firmware, B2368 66 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei B2368 22 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei B2368 57 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei B2368 66 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.