CVE-2020-1861
Estado: ModificadaMedia (4.4)—
CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 4.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-1861",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "CloudEngine 12800",
"versions": [
{
"status": "affected",
"version": "V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300"
}
]
}
]
}
],
"published": "2020-02-28T19:15:11.780",
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-01-leak-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-01-leak-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage vulnerability in some Huawei products. In some special cases, an authenticated attacker can exploit this vulnerability because the software processes data improperly. Successful exploitation may lead to information leakage."
},
{
"lang": "es",
"value": "CloudEngine 12800 con versiones de V200R001C00SPC600, V200R001C00SPC700, V200R002C01, V200R002C50SPC800, V200R002C50SPC800PWE, V200R003C00SPC810, V200R003C00SPC810PWE, V200R005C00SPC600, V200R005C00SPC800, V200R005C00SPC800PWE, V200R005C10, V200R005C10SPC300, presentan una vulnerabilidad de filtrado de información en algunos productos Huawei. En algunos casos especiales, un atacante autenticado puede explotar esta vulnerabilidad porque el software procesa los datos inapropiadamente. Una explotación con éxito puede conllevar a un filtrado de información."
}
],
"lastModified": "2026-06-17T03:02:30.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r001c00spc600:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1985052F-6452-46C7-8070-2CDB6FDF3803"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r001c00spc700:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA9CCEB1-6A35-4AE7-8F8D-EC137F663A85"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c01:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A7B1A3E-5D5A-4E3A-89F1-73DA7FF0F060"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c50spc800:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2A1D568-48C6-4CE4-8CD2-93F79F484448"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c50spc800pwe:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30198A99-3F26-4A98-A001-633508FA0EF3"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r003c00spc810:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32438232-3341-4056-B801-AA8F0F9E8DEC"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r003c00spc810pwe:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5EBD4506-36FE-407C-871C-943BF61696BE"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r005c00spc600:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F658926-A076-473C-B817-8D033FCB8A0E"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r005c00spc800:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32EF3B57-0B07-40C0-943D-2C21EEE4D747"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r005c00spc800pwe:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D8DF510-196D-4978-BBD5-FC753D7D36E9"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r005c10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "433BD50B-C8A5-4F0B-8905-18131C9FD364"
},
{
"criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r005c10spc300:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "548D3F5C-F473-419B-A935-3A3CDE749923"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:cloudengine_12800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DE8A2875-0F7E-4790-A925-5999396B7578"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}