CVE-2020-9075

MEDIUMCVSS 6.5/10EPSS 0.61%

Last modified

CVE-2020-9075 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. EPSS estimates a 0.61% chance of exploitation in the next 30 days.

Description

Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful exploitation of this vulnerability may lead to information leakage.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.61%

44.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HuaweiSecospace Usg6300 Firmwarev500r005c00
HuaweiSecospace Usg6300 Firmwarev500r005c10
HuaweiSecospace Usg6600 Firmwarev500r001c30
HuaweiSecospace Usg6600 Firmwarev500r001c50
HuaweiSecospace Usg6600 Firmwarev500r001c60
HuaweiSecospace Usg6600 Firmwarev500r001c80
HuaweiUsg6300e Firmwarev600r006c00

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-9075?
Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful exploitation of this vulnerability may lead to information leakage.
How severe is CVE-2020-9075?
CVE-2020-9075 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.61% probability of exploitation in the next 30 days.
How do I fix CVE-2020-9075?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-9075?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST