SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1879

There is an improper integrity checking vulnerability on some huawei products.

LOW 3.9EPSS 0.15%

Does this matter?

Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.

Description

There is an improper integrity checking vulnerability on some huawei products. The software of the affected product has an improper integrity check which may allow an attacker with high privilege to make malicious modifications.Affected product versions include:HEGE-560 versions 1.0.1.21(SP3);HEGE-570 versions 1.0.1.22(SP3);OSCA-550 versions 1.0.1.21(SP3);OSCA-550A versions 1.0.1.21(SP3);OSCA-550AX versions 1.0.1.21(SP3);OSCA-550X versions 1.0.1.21(SP3).

CVSS 3.1
3.9 LOWCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS
0.15% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-354
Affected
huawei/hege-560 firmware · huawei/hege-570 firmware · huawei/osca-550 firmware · huawei/osca-550a firmware · huawei/osca-550ax firmware · huawei/osca-550x firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.