Resource management error in eUDC660 - CVE-2020-9206

 

Resource management error in eUDC660 - CVE-2020-9206

Published: February 3, 2021


Vulnerability identifier: #VU50287
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-9206
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
eUDC660
Software vendor:
Huawei

Description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to improper management of internal resources within the application. A local administrator can pass specially crafted data to the application, obtain the key file and decrypt data, affecting confidentiality, integrity, and availability of the device.


Remediation

Install updates from vendor's website.

External links