PT-2020-15083 · Huawei · Gaussdb 200

Published

2020-02-17

·

Updated

2021-07-21

·

CVE-2020-1811

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GaussDB 200 version 6.5.1
Description The issue is related to a command injection vulnerability due to insufficient input validation. Remote attackers with low permissions could exploit this by sending crafted commands to the affected device, potentially allowing them to execute commands.
Recommendations For GaussDB 200 version 6.5.1, consider restricting access to the device to minimize the risk of exploitation until a patch is available. As a temporary workaround, ensure that all inputs are thoroughly validated to prevent the injection of malicious commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1811

Affected Products

Gaussdb 200