Information disclosure in Huawei products - CVE-2020-1856
Published: February 7, 2020
Vulnerability identifier: #VU25024
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1856
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to improper input validation. A remote attacker can send specific request packets to affected devices and gain unauthorized access to sensitive information.
Affected software
Huawei NGFW Module
Huawei NIP6300
Huawei NIP6600
USG9500
Huawei Secospace USG6600
Huawei Secospace USG6500
Huawei NIP6300
Huawei NIP6600
USG9500
Huawei Secospace USG6600
Huawei Secospace USG6500
How to mitigate CVE-2020-1856
Install updates from vendor's website.
Huawei NGFW Module - update to V500R005C20SPC300
Huawei NIP6300 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6600 - update to V500R005C20SPC300
Huawei Secospace USG6600 - update to V500R005C20SPC300
Huawei Secospace USG6500 - update to V500R005C20SPC300
Huawei NIP6300 - update to V500R005C20SPC300
USG9500 - update to V500R005C20SPC300
Huawei NIP6600 - update to V500R005C20SPC300
Huawei Secospace USG6600 - update to V500R005C20SPC300
Huawei Secospace USG6500 - update to V500R005C20SPC300