Vulnerability Description
Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device information. Successful exploit may cause service abnormal.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Hege-560 Firmware | 1.0.1.21\(sp3\) |
| Huawei | Hege-560 | - |
| Huawei | Osca-550 Firmware | 1.0.1.21\(sp3\) |
| Huawei | Osca-550 | - |
| Huawei | Osca-550A Firmware | 1.0.1.21\(sp3\) |
| Huawei | Osca-550A | - |
| Huawei | Osca-550Ax Firmware | 1.0.1.21\(sp3\) |
| Huawei | Osca-550Ax | - |
| Huawei | Osca-550X Firmware | 1.0.1.21\(sp3\) |
| Huawei | Osca-550X | - |
| Huawei | Hege-570 Firmware | 1.0.1.22\(sp3\) |
| Huawei | Hege-570 | - |
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-03-osca-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-03-osca-enVendor Advisory
FAQ
What is CVE-2020-1855?
CVE-2020-1855 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the de...
How severe is CVE-2020-1855?
CVE-2020-1855 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1855?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Hege-560 Firmware, Huawei Hege-560, Huawei Osca-550 Firmware, Huawei Osca-550, Huawei Osca-550A Firmware.