CVE-2020-9122

Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abnormal on affected devices.Affected product versions include:HiRouter-CD30-10 version 10.0.2.5;HiRouter-CT31-10 version 10.0.2.20;WS5200-12 version 10.0.1.9;WS5281-10 version 10.0.5.10;WS5800-10 version 10.0.3.25;WS7100-10 version 10.0.5.21;WS7200-10 version 10.0.5.21.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
huaweiCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
VendorProductVersion
huaweihirouter-cd30-10_firmware
10.0.2.5 ≤
𝑥
< 10.0.5.7
huaweihirouter-ct31-10_firmware
10.0.2.20 ≤
𝑥
< 10.0.2.37
huaweiws5200-12_firmware
10.0.1.9 ≤
𝑥
≤ 10.0.5.6
huaweiws5281-10_firmware
10.0.5.10 ≤
𝑥
< 10.0.5.32
huaweiws5800-10_firmware
10.0.3.25 ≤
𝑥
< 10.0.3.33
huaweiws7100-10_firmware
10.0.5.21 ≤
𝑥
< 10.0.5.37
huaweiws7200-10_firmware
10.0.5.21 ≤
𝑥
< 10.0.5.37
𝑥
= Vulnerable software versions