Vulnerability Description
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Gaussdb 200 | 6.5.1 |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-gaussdVendor Advisory
FAQ
What is CVE-2020-1811?
CVE-2020-1811 is a vulnerability with a CVSS score of 8.8 (HIGH). GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafte...
How severe is CVE-2020-1811?
CVE-2020-1811 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1811?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Gaussdb 200.