#VU49564 Improper validation of integrity check value in Huawei Myna - CVE-2020-9210

 

#VU49564 Improper validation of integrity check value in Huawei Myna - CVE-2020-9210

Published: January 18, 2021


Vulnerability identifier: #VU49564
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-9210
CWE-ID: CWE-354
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Huawei Myna
Software vendor:
Huawei

Description

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to a module does not perform sufficient integrity check. An attacker with physical access can install malware and compromise normal service of the affected device.


Remediation

Install updates from vendor's website.

External links