Some Huawei products have a command injection vulnerability
Published Nov 13, 2020
6.7
MEDIUMCVSS 3.1
EPSS 0.39%
Description
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospace USG6300 versions V500R001C30,V500R001C60;Secospace USG6500 versions V500R001C30,V500R001C60;Secospace USG6600 versions V500R001C30,V500R001C60;USG9500 versions V500R001C30,V500R001C60.
Affected products
- Vendor n/a Product NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 Defaultn/a
- Version V500R001C30,V500R001C60StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 | n/a |
|
Configuration 1
- v500r001c30
- v500r001c60
Configuration 2
- v500r001c30
- v500r001c60
Configuration 3
- v500r001c30
- v500r001c60
Running on/with
- n/a
Configuration 4
- v500r001c30
- v500r001c60
Running on/with
- n/a
Configuration 5
- v500r001c30
- v500r001c60
Running on/with
- n/a
Configuration 6
- v500r001c30
- v500r001c60
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29956 Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201111-02-injection-en x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29956 | Advisory | |
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201111-02-injection-en | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.