4.6
CVSSv2

CVE-2020-9137

Published: 24/12/2020 Updated: 28/12/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei cloudengine_12800_firmware v200r002c50spc800

huawei cloudengine_12800_firmware v200r003c00spc810

huawei cloudengine_12800_firmware v200r005c00spc800

huawei cloudengine_12800_firmware v200r005c10spc800

huawei cloudengine_12800_firmware v200r019c00spc800

huawei cloudengine_12800_firmware v200r019c10spc800

huawei cloudengine_5800_firmware v200r002c50spc800

huawei cloudengine_5800_firmware v200r003c00spc810

huawei cloudengine_5800_firmware v200r005c00spc800

huawei cloudengine_5800_firmware v200r005c10spc800

huawei cloudengine_5800_firmware v200r019c00spc800

huawei cloudengine_5800_firmware v200r019c10spc800

huawei cloudengine_6800_firmware v200r002c50spc800

huawei cloudengine_6800_firmware v200r003c00spc810

huawei cloudengine_6800_firmware v200r005c00spc800

huawei cloudengine_6800_firmware v200r005c10spc800

huawei cloudengine_6800_firmware v200r005c20spc800

huawei cloudengine_6800_firmware v200r019c00spc800

huawei cloudengine_6800_firmware v200r019c10spc800

huawei cloudengine_7800_firmware v200r002c50spc800

huawei cloudengine_7800_firmware v200r003c00spc810

huawei cloudengine_7800_firmware v200r005c00spc800

huawei cloudengine_7800_firmware v200r005c10spc800

huawei cloudengine_7800_firmware v200r019c00spc800

huawei cloudengine_7800_firmware v200r019c10spc800