CVE-2020-1864
Summary
| CVE | CVE-2020-1864 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-20 15:15:00 UTC |
| Updated | 2020-03-23 21:47:00 UTC |
| Description | Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affected device. Due to the improper implementation of the authentication function, attackers can exploit the vulnerability to connect to affected devices and execute a series of commands.Affected product versions include:Secospace AntiDDoS8000 versions V500R001C00,V500R001C20,V500R001C60,V500R005C00. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Secospace Antiddos8000 | - | All | All | All |
| Hardware | Huawei | Secospace Antiddos8000 | - | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c00 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c20 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c60 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r005c00 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c00 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c20 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r001c60 | All | All | All |
| Operating System | Huawei | Secospace Antiddos8000 Firmware | v500r005c00 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Improper Authentication Vulnerability in Some Huawei Products | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.