CVE-2020-1841

HIGHCVSS 7.5/10EPSS 0.97%

Last modified

CVE-2020-1841 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60 versions V500R002C00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C10, V600R019C00, and V600R019C00SPC100 have an information leak vulnerability. An unauthenticated, remote attacker can make a large number of attempts to guess information. EPSS estimates a 0.97% chance of exploitation in the next 30 days.

Description

Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60 versions V500R002C00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C10, V600R019C00, and V600R019C00SPC100 have an information leak vulnerability. An unauthenticated, remote attacker can make a large number of attempts to guess information. Successful exploitation may cause information leak.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.97%

57.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
HuaweiCloudlink Board Firmware20.0.0
HuaweiDp300 Firmwarev500r002c00
HuaweiRse6500 Firmwarev100r001c00
HuaweiRse6500 Firmwarev500r002c00
HuaweiRse6500 Firmwarev500r002c00spc900
HuaweiTe60 Firmwarev500r002c00
HuaweiTe60 Firmwarev600r006c00
HuaweiTe60 Firmwarev600r006c00spc200
HuaweiTe60 Firmwarev600r006c00spc300
HuaweiTe60 Firmwarev600r006c10
HuaweiTe60 Firmwarev600r019c00
HuaweiTe60 Firmwarev600r019c00spc100

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-1841?
Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60 versions V500R002C00, V600R006C00, V600R006C00SPC200, V600R006C00SPC300, V600R006C10, V600R019C00, and V600R019C00SPC100 have an information leak vulnerability. An unauthenticated, remote attacker can make a large number of attempts to guess information. Successful exploitation may cause information leak.
How severe is CVE-2020-1841?
CVE-2020-1841 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.97% probability of exploitation in the next 30 days.
How do I fix CVE-2020-1841?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-1841?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST