CVE-2020-1825
Last modified
CVE-2020-1825 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vulnerability by sending constructed messages to the affected device through another device on the same network. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vulnerability by sending constructed messages to the affected device through another device on the same network. Successful exploit could cause affected devices to be abnormal.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Fusionaccess | < 6.5.1.spc002 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1825?
How severe is CVE-2020-1825?
How do I fix CVE-2020-1825?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-18229Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote a…4.8
- CVE-2020-1823There are multiple out of bounds (OOB) read vulnerabilities …5.3
- CVE-2020-18230Cross Site Scripting (XSS) in PHPMyWind v5.5 allows remote a…4.8
- CVE-2020-18232Buffer Overflow vulnerability in function H5S_close in H5S.c…8.8
- CVE-2020-1824There are multiple out of bounds (OOB) read vulnerabilities …5.3
- CVE-2020-18243SQL injection vulnerability found in Enricozab CMS v.1.0 all…6.5
- CVE-2020-18259ED01-CMS v1.0 was discovered to contain a reflective cross-s…6.1
- CVE-2020-1826Huawei Honor Magic2 mobile phones with versions earlier than…4.4
- CVE-2020-18261An arbitrary file upload vulnerability in the image upload f…9.8
- CVE-2020-18262ED01-CMS v1.0 was discovered to contain a SQL injection in t…9.8
- CVE-2020-18263PHP-CMS v1.0 was discovered to contain a SQL injection vulne…7.5
- CVE-2020-18264Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows …8.8
Are you affected by CVE-2020-1825?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
