PT-2020-20544 · Huawei · Huawei Fusioncompute

Published

2020-07-31

·

Updated

2021-07-21

·

CVE-2020-9248

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei FusionComput version 8.0.0
Description The issue is related to improper authorization. A module fails to correctly verify some input, resulting in the authorization of files with incorrect access. This can be exploited to launch a privilege escalation attack, potentially compromising normal service.
Recommendations For Huawei FusionComput version 8.0.0, update to a version that includes the fix for this issue, as the current version does not properly verify input and authorizes files incorrectly, leading to potential privilege escalation attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9248

Affected Products

Huawei Fusioncompute