« Volver al listado

CVE-2020-1843

Estado: ModificadaMedia (6.8)—

Huawei HEGE-560 version 1.0.1.20(SP2), OSCA-550 version 1.0.0.71(SP1), OSCA-550A version 1.0.0.71(SP1), OSCA-550AX version 1.0.0.71(SP2), and OSCA-550X version 1.0.0.71(SP2) have an insufficient verification vulnerability. An attacker can perform specific operations to exploit this vulnerability by physical access methods. Successful exploitation may cause the attacker perform an illegal operation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-1843",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei",
          "product": "HEGE-560",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.1.20(SP2)"
            }
          ]
        },
        {
          "vendor": "Huawei",
          "product": "OSCA-550",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.71(SP1)"
            }
          ]
        },
        {
          "vendor": "Huawei",
          "product": "OSCA-550A",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.71(SP1)"
            }
          ]
        },
        {
          "vendor": "Huawei",
          "product": "OSCA-550AX",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.71(SP2)"
            }
          ]
        },
        {
          "vendor": "Huawei",
          "product": "OSCA-550X",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.71(SP2)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-02-18T03:15:11.217",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-02-osca-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-02-osca-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Huawei HEGE-560 version 1.0.1.20(SP2), OSCA-550 version 1.0.0.71(SP1), OSCA-550A version 1.0.0.71(SP1), OSCA-550AX version 1.0.0.71(SP2), and OSCA-550X version 1.0.0.71(SP2) have an insufficient verification vulnerability. An attacker can perform specific operations to exploit this vulnerability by physical access methods. Successful exploitation may cause the attacker perform an illegal operation."
    },
    {
      "lang": "es",
      "value": "Huawei HEGE-560 versión 1.0.1.20(SP2), OSCA-550 versión 1.0.0.71(SP1), OSCA-550A versión 1.0.0.71(SP1), OSCA-550AX versión 1.0.0.71(SP2) y versión OSCA-550X 1.0.0.71(SP2), presentan una vulnerabilidad de comprobación insuficiente. Un atacante puede llevar a cabo operaciones específicas para explotar esta vulnerabilidad mediante métodos de acceso físico. Una explotación con éxito puede causar que el atacante realice una operación ilegal."
    }
  ],
  "lastModified": "2026-06-17T03:02:29.803",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:hege-560_firmware:1.0.1.20\\(sp2\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65CC8631-B76A-4EBC-AA9C-D53FB1D256CE"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:hege-560:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3325D5D9-8956-4335-B616-C553BF885152"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:osca-550_firmware:1.0.0.71\\(sp1\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FBE7C39-A376-4C6C-A8BB-A27AFC54770B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:osca-550:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C0D0122F-89FF-4B3E-8837-2E07A0D27105"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:osca-550a_firmware:1.0.0.71\\(sp1\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "665F1A21-5F7A-49CD-9051-53BCB06993B7"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:osca-550a:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5D4E574D-DEFF-48CC-81F0-28DB6432EF13"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:osca-550ax_firmware:1.0.0.71\\(sp2\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ADA1B36-992F-44A5-A5AE-FD9AC7772D0A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:osca-550ax:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "62EEE25C-2FA4-4B64-9680-387380D97352"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:osca-550x_firmware:1.0.0.71\\(sp2\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91C579FB-2CBB-4836-A7A6-C06131B2DB15"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:osca-550x:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "565AF527-86EF-4314-A645-B99D0C4C62C2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}