René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

105 lines
3.4 KiB
JSON

{
"id": "CVE-2020-1825",
"sourceIdentifier": "psirt@huawei.com",
"published": "2020-06-15T15:15:09.647",
"lastModified": "2020-06-18T19:54:33.777",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vulnerability by sending constructed messages to the affected device through another device on the same network. Successful exploit could cause affected devices to be abnormal."
},
{
"lang": "es",
"value": "FusionAccess con versiones anteriores a 6.5.1.SPC002, presentan una vulnerabilidad de denegaci\u00f3n de servicio (DoS). Debido a una verificaci\u00f3n insuficiente sobre una entrada espec\u00edfica, los atacantes pueden explotar esta vulnerabilidad mediante el env\u00edo de mensajes construidos hacia el dispositivo afectado por medio de otro dispositivo en la misma red. Una explotaci\u00f3n con \u00e9xito podr\u00eda causar que los dispositivos afectados sean anormales"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:fusionaccess:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.5.1.spc002",
"matchCriteriaId": "D1BA7C89-9020-419A-98FB-AE696F8F8B30"
}
]
}
]
}
],
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fusionacces-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}