ID

VAR-202002-0616


CVE

CVE-2020-1857


TITLE

plural Huawei Information leakage vulnerabilities in products

Trust: 0.8

sources: JVNDB: JVNDB-2020-002153

DESCRIPTION

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. Due to improper processing of some data, a local authenticated attacker can exploit this vulnerability through a series of operations. Successful exploitation may cause information leakage

Trust: 1.62

sources: NVD: CVE-2020-1857 // JVNDB: JVNDB-2020-002153

AFFECTED PRODUCTS

vendor:huaweimodel:nip6800scope:eqversion:v500r001c30

Trust: 1.8

vendor:huaweimodel:nip6800scope:eqversion:v500r001c60spc500

Trust: 1.8

vendor:huaweimodel:nip6800scope:eqversion:v500r005c00spc100

Trust: 1.8

vendor:huaweimodel:secospace usg6600scope:eqversion:v500r001c30spc200

Trust: 1.8

vendor:huaweimodel:secospace usg6600scope:eqversion:v500r001c30spc600

Trust: 1.8

vendor:huaweimodel:secospace usg6600scope:eqversion:v500r001c60spc500

Trust: 1.8

vendor:huaweimodel:secospace usg6600scope:eqversion:v500r005c00spc100

Trust: 1.8

vendor:huaweimodel:usg9500scope:eqversion:v500r001c30spc200

Trust: 1.8

vendor:huaweimodel:usg9500scope:eqversion:v500r001c30spc600

Trust: 1.8

vendor:huaweimodel:usg9500scope:eqversion:v500r001c60spc500

Trust: 1.8

vendor:huaweimodel:usg9500scope:eqversion:v500r005c00spc100

Trust: 1.8

sources: JVNDB: JVNDB-2020-002153 // NVD: CVE-2020-1857

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1857
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-002153
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202002-414
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-1857
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-002153
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-1857
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-002153
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-002153 // CNNVD: CNNVD-202002-414 // NVD: CVE-2020-1857

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-200

Trust: 0.8

sources: JVNDB: JVNDB-2020-002153 // NVD: CVE-2020-1857

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202002-414

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202002-414

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-002153

PATCH

title:huawei-sa-20200205-01-leakageurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200205-01-leakage-en

Trust: 0.8

title:Huawei NIP6800 , Secospace USG6600 and USG9500 Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=110184

Trust: 0.6

sources: JVNDB: JVNDB-2020-002153 // CNNVD: CNNVD-202002-414

EXTERNAL IDS

db:NVDid:CVE-2020-1857

Trust: 2.4

db:JVNDBid:JVNDB-2020-002153

Trust: 0.8

db:CNNVDid:CNNVD-202002-414

Trust: 0.6

sources: JVNDB: JVNDB-2020-002153 // CNNVD: CNNVD-202002-414 // NVD: CVE-2020-1857

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200205-01-leakage-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-1857

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1857

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200205-01-leakage-cn

Trust: 0.6

sources: JVNDB: JVNDB-2020-002153 // CNNVD: CNNVD-202002-414 // NVD: CVE-2020-1857

SOURCES

db:JVNDBid:JVNDB-2020-002153
db:CNNVDid:CNNVD-202002-414
db:NVDid:CVE-2020-1857

LAST UPDATE DATE

2024-11-23T22:16:38.905000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-002153date:2020-03-05T00:00:00
db:CNNVDid:CNNVD-202002-414date:2020-12-31T00:00:00
db:NVDid:CVE-2020-1857date:2024-11-21T05:11:29.713

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-002153date:2020-03-05T00:00:00
db:CNNVDid:CNNVD-202002-414date:2020-02-05T00:00:00
db:NVDid:CVE-2020-1857date:2020-02-17T20:15:11.633