PT-2020-15125 · Huawei · Usg9500+3

Published

2020-02-19

·

Updated

2021-07-21

·

CVE-2020-1860

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NIP6800 versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100 Secospace USG6600 versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100 USG9500 products versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100
Description The issue is an access control bypass vulnerability. Attackers with access to the internal network can exploit this vulnerability with careful deployment. Successful exploitation may cause the access control to be bypassed, allowing attackers to directly access the Internet.
Recommendations For NIP6800 versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100, restrict access to internal networks to minimize the risk of exploitation. For Secospace USG6600 versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100, consider implementing additional security measures to prevent careful deployment by attackers. For USG9500 products versions V500R001C30; V500R001C60SPC500; V500R005C00SPC100, limit direct Internet access until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-1860

Affected Products

Huawei Vrp
Nip6800
Secospace Usg6600
Usg9500