CVE-2020-9222

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:huawei:fusioncompute:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:8.0.0:-:*:*:*:*:*:*

History

15 Jan 2025, 14:50

Type Values Removed Values Added
CPE cpe:2.3:h:huawei:fusioncompute:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.3.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:8.0.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.5.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.3.1:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.5.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.5.0:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.3.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:8.0.0:-:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.3.0:*:*:*:*:*:*:*
cpe:2.3:a:huawei:fusioncompute:6.5.1:*:*:*:*:*:*:*

13 Jan 2025, 18:49

Type Values Removed Values Added
First Time Huawei fusioncompute Firmware
Huawei fusioncompute
Huawei
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:huawei:fusioncompute_firmware:6.3.1:*:*:*:*:*:*:*
cpe:2.3:h:huawei:fusioncompute:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.3.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:8.0.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.5.1:*:*:*:*:*:*:*
cpe:2.3:o:huawei:fusioncompute_firmware:6.5.0:*:*:*:*:*:*:*
References () https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-01-fc-en - () https://www.huawei.com/en/psirt/security-advisories/2020/huawei-sa-20200826-01-fc-en - Vendor Advisory
Summary
  • (es) Existe una vulnerabilidad de escalada de privilegios en el producto Huawei FusionCompute. Debido a la verificación insuficiente de archivos específicos que deben deserializarse, los atacantes locales pueden aprovechar esta vulnerabilidad para elevar los permisos. (ID de vulnerabilidad: HWPSIRT-2020-05241) A esta vulnerabilidad se le ha asignado un ID de vulnerabilidad y exposición común (CVE): CVE-2020-9222.

27 Dec 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-27 10:15

Updated : 2025-01-15 14:50


NVD link : CVE-2020-9222

Mitre link : CVE-2020-9222

CVE.ORG link : CVE-2020-9222


JSON object : View

Products Affected

huawei

  • fusioncompute
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo