CVE-2020-9222
HIGH
7,0
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0001
Percentile
0,0th
Updated
EPSS Score Trend (Last 90 Days)
269
Improper Privilege Management
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
Application
Fusioncompute by Huawei
CPE Identifier
View Detailed Analysis
cpe:2.3:a:huawei:fusioncompute:8.0.0:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Fusioncompute by Huawei
CPE Identifier
View Detailed Analysis
cpe:2.3:a:huawei:fusioncompute:6.3.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Fusioncompute by Huawei
CPE Identifier
View Detailed Analysis
cpe:2.3:a:huawei:fusioncompute:6.5.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Fusioncompute by Huawei
CPE Identifier
View Detailed Analysis
cpe:2.3:a:huawei:fusioncompute:6.3.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Fusioncompute by Huawei
CPE Identifier
View Detailed Analysis
cpe:2.3:a:huawei:fusioncompute:6.5.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-01-…