{"api_version":"1","generated_at":"2026-07-23T14:28:54+00:00","cve":"CVE-2020-1811","urls":{"html":"https://cve.report/CVE-2020-1811","api":"https://cve.report/api/cve/CVE-2020-1811.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-1811","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-1811"},"summary":{"title":"CVE-2020-1811","description":"GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands.","state":"PUBLIC","assigner":"psirt@huawei.com","published_at":"2020-02-18 00:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-20","CWE-77"],"metrics":[],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdb200-en","name":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdb200-en","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Advisory - Command Injection Vulnerability in GaussDB 200 Product","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-1811","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-1811","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"1811","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"huawei","cpe5":"gaussdb_200","cpe6":"6.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"1811","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"huawei","cpe5":"gaussdb_200","cpe6":"6.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-1811","ASSIGNER":"psirt@huawei.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Huawei","product":{"product_data":[{"product_name":"GaussDB 200","version":{"version_data":[{"version_value":"6.5.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Command Injection"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdb200-en","url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdb200-en"}]},"description":{"description_data":[{"lang":"eng","value":"GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands."}]}},"nvd":{"publishedDate":"2020-02-18 00:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-20","CWE-77"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:huawei:gaussdb_200:6.5.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"1811","Ordinal":"161140","Title":"CVE-2020-1811","CVE":"CVE-2020-1811","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"1811","Ordinal":"1","NoteData":"GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"1811","Ordinal":"2","NoteData":"2020-02-17","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"1811","Ordinal":"3","NoteData":"2020-02-17","Type":"Other","Title":"Modified"}]}}}