Insufficient verification of data authenticity in Huawei products - CVE-2020-1843

 

Insufficient verification of data authenticity in Huawei products - CVE-2020-1843

Published: January 24, 2020


Vulnerability identifier: #VU24514
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1843
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform an illegal operation on the target device.

The vulnerability exists due to an insufficient verification issue. An attacker with physical access can perform specific operations, leading to an illegal operation.


Affected software

OSCA-550
OSCA-550A
OSCA-550AX
OSCA-550X
Huawei HEGE-560

How to mitigate CVE-2020-1843

Install updates from vendor's website.

OSCA-550 - update to 1.0.1.21(SP3)
OSCA-550A - update to 1.0.1.21(SP3)
OSCA-550AX - update to 1.0.1.21(SP3)
OSCA-550X - update to 1.0.1.21(SP3)
Huawei HEGE-560 - update to 1.0.1.21(SP3)

External References

Related Security Bulletins