Show plain JSON{"id": "CVE-2020-1842", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.8, "attackVector": "PHYSICAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 0.9}]}, "published": "2020-02-18T04:15:14.507", "references": [{"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-osca-en", "tags": ["Vendor Advisory"], "source": "psirt@huawei.com"}, {"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-osca-en", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "Huawei HEGE-560 version 1.0.1.20(SP2); OSCA-550 and OSCA-550A version 1.0.0.71(SP1); and OSCA-550AX and OSCA-550X version 1.0.0.71(SP2) have an insufficient authentication vulnerability. An attacker can access the device physically and perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker obtain high privilege."}, {"lang": "es", "value": "Huawei HEGE-560 versi\u00f3n 1.0.1.20(SP2); OSCA-550 y OSCA-550A versi\u00f3n 1.0.0.71(SP1); y OSCA-550AX y OSCA-550X versi\u00f3n 1.0.0.71(SP2), presentan una vulnerabilidad de autenticaci\u00f3n insuficiente. Un atacante puede acceder al dispositivo f\u00edsicamente y llevar a cabo operaciones espec\u00edficas para explotar esta vulnerabilidad. Una explotaci\u00f3n con \u00e9xito puede causar que el atacante obtenga privilegios altos."}], "lastModified": "2024-11-21T05:11:28.567", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hege-560_firmware:1.0.1.20\\(sp2\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65CC8631-B76A-4EBC-AA9C-D53FB1D256CE"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hege-560:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3325D5D9-8956-4335-B616-C553BF885152"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:osca-550_firmware:1.0.0.71\\(sp1\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FBE7C39-A376-4C6C-A8BB-A27AFC54770B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:osca-550:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C0D0122F-89FF-4B3E-8837-2E07A0D27105"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:osca-550a_firmware:1.0.0.71\\(sp1\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "665F1A21-5F7A-49CD-9051-53BCB06993B7"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:osca-550a:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5D4E574D-DEFF-48CC-81F0-28DB6432EF13"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:osca-550ax_firmware:1.0.0.71\\(sp2\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8ADA1B36-992F-44A5-A5AE-FD9AC7772D0A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:osca-550ax:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "62EEE25C-2FA4-4B64-9680-387380D97352"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:osca-550x_firmware:1.0.0.71\\(sp2\\):*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "91C579FB-2CBB-4836-A7A6-C06131B2DB15"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:osca-550x:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "565AF527-86EF-4314-A645-B99D0C4C62C2"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "psirt@huawei.com"}