ID

VAR-202008-1046


CVE

CVE-2020-9242


TITLE

FusionCompute In OS Command injection vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2020-009596

DESCRIPTION

FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack. FusionCompute To OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. Huawei FusionCompute is a computer virtualization engine developed by Huawei in China. The product provides Virtual Resource Manager (VRM) and Compute Node Agent (CNA), etc. The vulnerability is caused by the device not fully verifying some parameters submitted by the user. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements

Trust: 1.8

sources: NVD: CVE-2020-9242 // JVNDB: JVNDB-2020-009596 // VULHUB: VHN-187367 // VULMON: CVE-2020-9242

AFFECTED PRODUCTS

vendor:huaweimodel:fusioncomputescope:eqversion:8.0.0

Trust: 1.8

sources: JVNDB: JVNDB-2020-009596 // NVD: CVE-2020-9242

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9242
value: HIGH

Trust: 1.0

NVD: JVNDB-2020-009596
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202008-697
value: HIGH

Trust: 0.6

VULHUB: VHN-187367
value: MEDIUM

Trust: 0.1

VULMON: CVE-2020-9242
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-9242
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-009596
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-187367
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-9242
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-009596
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-187367 // VULMON: CVE-2020-9242 // JVNDB: JVNDB-2020-009596 // CNNVD: CNNVD-202008-697 // NVD: CVE-2020-9242

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.1

problemtype:CWE-78

Trust: 0.9

sources: VULHUB: VHN-187367 // JVNDB: JVNDB-2020-009596 // NVD: CVE-2020-9242

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202008-697

TYPE

operating system commend injection

Trust: 0.6

sources: CNNVD: CNNVD-202008-697

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-009596

PATCH

title:huawei-sa-20200812-01-computeurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200812-01-compute-en

Trust: 0.8

title:Huawei FusionCompute Fixes for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=126708

Trust: 0.6

sources: JVNDB: JVNDB-2020-009596 // CNNVD: CNNVD-202008-697

EXTERNAL IDS

db:NVDid:CVE-2020-9242

Trust: 2.6

db:JVNDBid:JVNDB-2020-009596

Trust: 0.8

db:CNNVDid:CNNVD-202008-697

Trust: 0.7

db:NSFOCUSid:48743

Trust: 0.6

db:CNVDid:CNVD-2020-46458

Trust: 0.1

db:VULHUBid:VHN-187367

Trust: 0.1

db:VULMONid:CVE-2020-9242

Trust: 0.1

sources: VULHUB: VHN-187367 // VULMON: CVE-2020-9242 // JVNDB: JVNDB-2020-009596 // CNNVD: CNNVD-202008-697 // NVD: CVE-2020-9242

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200812-01-compute-en

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2020-9242

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9242

Trust: 0.8

url:http://www.nsfocus.net/vulndb/48743

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200812-01-compute-cn

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/77.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-187367 // VULMON: CVE-2020-9242 // JVNDB: JVNDB-2020-009596 // CNNVD: CNNVD-202008-697 // NVD: CVE-2020-9242

SOURCES

db:VULHUBid:VHN-187367
db:VULMONid:CVE-2020-9242
db:JVNDBid:JVNDB-2020-009596
db:CNNVDid:CNNVD-202008-697
db:NVDid:CVE-2020-9242

LAST UPDATE DATE

2024-11-23T23:01:19.109000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-187367date:2021-07-21T00:00:00
db:VULMONid:CVE-2020-9242date:2021-07-21T00:00:00
db:JVNDBid:JVNDB-2020-009596date:2020-11-20T06:26:52
db:CNNVDid:CNNVD-202008-697date:2021-08-16T00:00:00
db:NVDid:CVE-2020-9242date:2024-11-21T05:40:14.510

SOURCES RELEASE DATE

db:VULHUBid:VHN-187367date:2020-08-17T00:00:00
db:VULMONid:CVE-2020-9242date:2020-08-17T00:00:00
db:JVNDBid:JVNDB-2020-009596date:2020-11-20T06:26:52
db:CNNVDid:CNNVD-202008-697date:2020-08-12T00:00:00
db:NVDid:CVE-2020-9242date:2020-08-17T15:15:15.417