CVE-2020-1802
Summary
| CVE | CVE-2020-1802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-10 14:15:00 UTC |
| Updated | 2020-04-13 13:54:00 UTC |
| Description | There is an insufficient integrity validation vulnerability in several products. The device does not sufficiently validate the integrity of certain file in certain loading processes, successful exploit could allow the attacker to load a crafted file to the device through USB.Affected product versions include:OSCA-550 versions 1.0.1.23(SP2);OSCA-550A versions 1.0.1.23(SP2);OSCA-550AX versions 1.0.1.23(SP2);OSCA-550X versions 1.0.1.23(SP2). |
Risk And Classification
Problem Types: CWE-354
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Osca-550 | - | All | All | All |
| Hardware | Huawei | Osca-550 | - | All | All | All |
| Hardware | Huawei | Osca-550a | - | All | All | All |
| Hardware | Huawei | Osca-550a | - | All | All | All |
| Hardware | Huawei | Osca-550ax | - | All | All | All |
| Hardware | Huawei | Osca-550ax | - | All | All | All |
| Operating System | Huawei | Osca-550ax Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550ax Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550a Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550a Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Hardware | Huawei | Osca-550x | - | All | All | All |
| Hardware | Huawei | Osca-550x | - | All | All | All |
| Operating System | Huawei | Osca-550x Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550x Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550 Firmware | 1.0.1.23\(sp2\) | All | All | All |
| Operating System | Huawei | Osca-550 Firmware | 1.0.1.23\(sp2\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Insufficient Integrity Validation Vulnerability in Several Products | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.