CVE-2020-1879
There is an improper integrity checking vulnerability on some huawei products.
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions 1.0.1.22(SP3);OSCA-550 versions 1.0.1.21(SP3);OSCA-550A versions 1.0.1.21(SP3);OSCA-550AX versions 1.0.1.21(SP3);OSCA-550X versions 1.0.1.21(SP3).
- CVSS 3.1
- 3.9 LOWCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.15% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354
- Affected
- huawei/hege-560 firmware · huawei/hege-570 firmware · huawei/osca-550 firmware · huawei/osca-550a firmware · huawei/osca-550ax firmware · huawei/osca-550x firmware
- Source
- psirt@huawei.com
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-enNot Applicable
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-integrity-enVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-enNot Applicable
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-integrity-enVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.