HIGH
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability
Published Dec 1, 2020
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.
Affected products
- Vendor n/a Product FusionCompute Defaultn/a
- Version 6.3.0,6.3.1,6.5.0,6.5.1,8.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | FusionCompute | n/a |
|
OR
- 6.3.0
- 6.3.1
- 6.5.0
- 6.5.1
- 8.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29943 Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201118-01-privilege-en x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29943 | Advisory | |
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201118-01-privilege-en | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner huawei
Published Dec 1, 2020
Updated Aug 4, 2024
Reserved Feb 18, 2020
Link CVE-2020-9114
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-29943 Assigner huawei
Published Dec 1, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-29943