CVE-2020-9209
Last modified
CVE-2020-9209 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the directory limitation. Attackers can exploit this vulnerability by crafting malicious file to launch privilege escalation. This can compromise normal service of affected products.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Smc2.0 Firmware | v600r006c00spc700 |
| Huawei | Smc2.0 Firmware | v600r006c00spc800 |
| Huawei | Smc2.0 Firmware | v600r006c10spc500 |
| Huawei | Smc2.0 Firmware | v600r006c10spc600 |
| Huawei | Smc2.0 Firmware | v600r006c10spc601 |
| Huawei | Smc2.0 Firmware | v600r006c10spc602 |
| Huawei | Smc2.0 Firmware | v600r006c10spc700 |
| Huawei | Smc2.0 Firmware | v600r006c10spc800 |
| Huawei | Smc2.0 Firmware | v600r006c10spca00 |
| Huawei | Smc2.0 Firmware | v600r006c10spcb00 |
| Huawei | Smc2.0 Firmware | v600r006c10spcc00 |
| Huawei | Smc2.0 Firmware | v600r006c10spcd00 |
| Huawei | Smc2.0 Firmware | v600r006c10spce00 |
| Huawei | Smc2.0 Firmware | v600r019c00 |
| Huawei | Smc2.0 Firmware | v600r019c10 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9209?
How severe is CVE-2020-9209?
How do I fix CVE-2020-9209?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9202There is an information disclosure vulnerability in TE Mobil…4.4
- CVE-2020-9203There is a resource management errors vulnerability in Huawe…3.3
- CVE-2020-9205There has a CSV injection vulnerability in ManageOne 8.0.1. …4.9
- CVE-2020-9206The eUDC660 product has a resource management vulnerability.…6.7
- CVE-2020-9207There is an improper authentication vulnerability in some ve…7.8
- CVE-2020-9208There is an information leak vulnerability in iManager NetEc…6.5
- CVE-2020-9210There is an insufficient integrity vulnerability in Huawei p…6.8
- CVE-2020-9211There is an out-of-bound read and write vulnerability in Hua…7.2
- CVE-2020-9212There is a vulnerability in some version of USG9500 that the…6.5
- CVE-2020-9213There is a denial of service vulnerability in some huawei pr…7.5
- CVE-2020-9222There is a privilege escalation vulnerability in Huawei Fusi…7.8
- CVE-2020-9223There is a denial of service vulnerability in some Huawei sm…7.5
Are you affected by CVE-2020-9209?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
