PT-2020-20492 · Huawei · Hisuite

Eran Shimony

·

Published

2020-07-06

·

Updated

2021-07-21

·

CVE-2020-9100

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HiSuite versions prior to 10.1.0.500
Description The issue exists due to improper loading of a DLL file by HiSuite, allowing an attacker to load a DLL file of their choice. This is a result of a DLL hijacking vulnerability.
Recommendations For versions prior to 10.1.0.500, update to version 10.1.0.500 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable DLL files to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9100

Affected Products

Hisuite