PT-2020-15115 · Huawei · Hege-560+2

Published

2020-02-18

·

Updated

2020-02-20

·

CVE-2020-1842

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei HEGE-560 version 1.0.1.20(SP2) OSCA-550 and OSCA-550A version 1.0.0.71(SP1) OSCA-550AX and OSCA-550X version 1.0.0.71(SP2)
Description The issue is related to insufficient authentication. An attacker can physically access the device and perform specific operations to exploit this. Successful exploitation may allow the attacker to obtain high privilege.
Recommendations For Huawei HEGE-560 version 1.0.1.20(SP2), update to a version that addresses the insufficient authentication issue. For OSCA-550 and OSCA-550A version 1.0.0.71(SP1), update to a version that addresses the insufficient authentication issue. For OSCA-550AX and OSCA-550X version 1.0.0.71(SP2), update to a version that addresses the insufficient authentication issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1842

Affected Products

Hege-560
Osca-550
Osca-550A