PT-2020-20544 · Huawei · Huawei Fusioncompute
Published
2020-07-31
·
Updated
2021-07-21
·
CVE-2020-9248
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei FusionComput version 8.0.0
Description
The issue is related to improper authorization. A module fails to correctly verify some input, resulting in the authorization of files with incorrect access. This can be exploited to launch a privilege escalation attack, potentially compromising normal service.
Recommendations
For Huawei FusionComput version 8.0.0, update to a version that includes the fix for this issue, as the current version does not properly verify input and authorizes files incorrectly, leading to potential privilege escalation attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei Fusioncompute