Information disclosure in Huawei products - CVE-2020-1856
Published: February 7, 2020
Vulnerability identifier: #VU25024
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1856
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Huawei
Affected software:
Huawei NGFW Module
Huawei NIP6300
Huawei NIP6600
Huawei Secospace USG6500
Huawei Secospace USG6600
USG9500
Huawei NGFW Module
Huawei NIP6300
Huawei NIP6600
Huawei Secospace USG6500
Huawei Secospace USG6600
USG9500
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper input validation. A remote attacker can send specific request packets to affected devices and gain unauthorized access to sensitive information.
How to mitigate CVE-2020-1856
Install updates from vendor's website.