Improper Authentication in Huawei products - CVE-2020-9207
Published: December 17, 2020
Vulnerability identifier: #VU49047
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9207
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a module does not verify the input file properly. A remote attacker can send specially crafted files to bypass current verification mechanism.
Affected software
Huawei CloudEngine 6800
Huawei CloudEngine 5800
Huawei CloudEngine 7800
Huawei CloudEngine 12800
Huawei CloudEngine 5800
Huawei CloudEngine 7800
Huawei CloudEngine 12800
How to mitigate CVE-2020-9207
Install updates from vendor's website.
Huawei CloudEngine 6800 - update to V200R019C10SPC800
Huawei CloudEngine 12800 - update to V200R019C10SPC800
Huawei CloudEngine 5800 - update to V200R019C10SPC800
Huawei CloudEngine 7800 - update to V200R019C10SPC800
Huawei CloudEngine 12800 - update to V200R019C10SPC800
Huawei CloudEngine 5800 - update to V200R019C10SPC800
Huawei CloudEngine 7800 - update to V200R019C10SPC800