CVE-2020-1810

MEDIUMCVSS 5.3/10EPSS 0.45%

Last modified

CVE-2020-1810 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. EPSS estimates a 0.45% chance of exploitation in the next 30 days.

Description

There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
0.45%

36.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiCloudengine 12800 Firmwarev100r003c00spc600
HuaweiCloudengine 12800 Firmwarev100r003c10spc100
HuaweiCloudengine 12800 Firmwarev100r005c00spc200
HuaweiCloudengine 12800 Firmwarev100r005c00spc300
HuaweiCloudengine 12800 Firmwarev100r005c10hp0001
HuaweiCloudengine 12800 Firmwarev100r005c10spc100
HuaweiCloudengine 12800 Firmwarev100r005c10spc200
HuaweiCloudengine 12800 Firmwarev100r006c00
HuaweiCloudengine 12800 Firmwarev200r001c00
HuaweiCloudengine 12800 Firmwarev200r002c01
HuaweiCloudengine 12800 Firmwarev200r002c10
HuaweiCloudengine 12800 Firmwarev200r002c20
HuaweiCloudengine 12800 Firmwarev200r005c10
HuaweiS5700 Firmwarev200r005c00spc500
HuaweiS5700 Firmwarev200r005c03
HuaweiS5700 Firmwarev200r006c00spc100
HuaweiS5700 Firmwarev200r006c00spc300
HuaweiS5700 Firmwarev200r006c00spc500
HuaweiS5700 Firmwarev200r007c00spc100
HuaweiS5700 Firmwarev200r007c00spc500
HuaweiS6700 Firmwarev200r005c00spc500
HuaweiS6700 Firmwarev200r005c01

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-1810?
There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.
How severe is CVE-2020-1810?
CVE-2020-1810 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.45% probability of exploitation in the next 30 days.
How do I fix CVE-2020-1810?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-1810?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST