ID

VAR-202004-1000


CVE

CVE-2020-1817


TITLE

Huawei PCManager Vulnerability related to authority management in

Trust: 0.8

sources: JVNDB: JVNDB-2020-004832

DESCRIPTION

Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can inject commands to exploit this vulnerability. Successful exploit may cause privilege escalation. Huawei PCManager Exists in a privilege management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Huawei PCManager is a set of computer management software developed by China Huawei (Huawei)

Trust: 1.8

sources: NVD: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // VULHUB: VHN-171421 // VULMON: CVE-2020-1817

AFFECTED PRODUCTS

vendor:huaweimodel:pcmanagerscope:ltversion:10.0.1.36

Trust: 1.0

vendor:huaweimodel:pcmanagerscope:eqversion:10.0.1.36

Trust: 0.8

vendor:huaweimodel:pcmanagerscope:eqversion:9.0.1.50

Trust: 0.1

vendor:huaweimodel:pcmanagerscope:eqversion:9.1.3.1

Trust: 0.1

sources: VULMON: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // NVD: CVE-2020-1817

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1817
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-004832
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202004-2437
value: HIGH

Trust: 0.6

VULHUB: VHN-171421
value: MEDIUM

Trust: 0.1

VULMON: CVE-2020-1817
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-1817
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-004832
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-171421
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-1817
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-004832
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-171421 // VULMON: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // CNNVD: CNNVD-202004-2437 // NVD: CVE-2020-1817

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-269

Trust: 0.9

sources: VULHUB: VHN-171421 // JVNDB: JVNDB-2020-004832 // NVD: CVE-2020-1817

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202004-2437

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202004-2437

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-004832

PATCH

title:huawei-sa-20200429-01-pcmanagerurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-pcmanager-en

Trust: 0.8

title:Huawei PCManager Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=117511

Trust: 0.6

title:Huawei Security Advisories: Security Advisory - Privilege Escalation Vulnerability in Huawei PCManager Producturl:https://vulmon.com/vendoradvisory?qidtp=huawei_security_advisories&qid=8cf31271005fded70a0afa24a3e6adb2

Trust: 0.1

sources: VULMON: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // CNNVD: CNNVD-202004-2437

EXTERNAL IDS

db:NVDid:CVE-2020-1817

Trust: 2.6

db:JVNDBid:JVNDB-2020-004832

Trust: 0.8

db:CNNVDid:CNNVD-202004-2437

Trust: 0.7

db:CNVDid:CNVD-2020-28978

Trust: 0.1

db:VULHUBid:VHN-171421

Trust: 0.1

db:VULMONid:CVE-2020-1817

Trust: 0.1

sources: VULHUB: VHN-171421 // VULMON: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // CNNVD: CNNVD-202004-2437 // NVD: CVE-2020-1817

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200429-01-pcmanager-en

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-1817

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1817

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200429-01-pcmanager-cn

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/269.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/181220

Trust: 0.1

sources: VULHUB: VHN-171421 // VULMON: CVE-2020-1817 // JVNDB: JVNDB-2020-004832 // CNNVD: CNNVD-202004-2437 // NVD: CVE-2020-1817

SOURCES

db:VULHUBid:VHN-171421
db:VULMONid:CVE-2020-1817
db:JVNDBid:JVNDB-2020-004832
db:CNNVDid:CNNVD-202004-2437
db:NVDid:CVE-2020-1817

LAST UPDATE DATE

2024-11-23T22:55:10.850000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-171421date:2021-07-21T00:00:00
db:VULMONid:CVE-2020-1817date:2020-05-05T00:00:00
db:JVNDBid:JVNDB-2020-004832date:2020-05-28T00:00:00
db:CNNVDid:CNNVD-202004-2437date:2020-05-06T00:00:00
db:NVDid:CVE-2020-1817date:2024-11-21T05:11:26.380

SOURCES RELEASE DATE

db:VULHUBid:VHN-171421date:2020-04-30T00:00:00
db:VULMONid:CVE-2020-1817date:2020-04-30T00:00:00
db:JVNDBid:JVNDB-2020-004832date:2020-05-28T00:00:00
db:CNNVDid:CNNVD-202004-2437date:2020-04-29T00:00:00
db:NVDid:CVE-2020-1817date:2020-04-30T22:15:11.947