ID

VAR-202010-1601


TITLE

H3C's H3C intrusion prevention system product iWare series has SQL injection vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2020-63989

DESCRIPTION

New H3C Technology Co., Ltd. is committed to becoming the most reliable partner for customers' business innovation and digital transformation. Main products include routers, big data, switches, Internet of Things, cloud computing, servers, etc. H3C's H3C intrusion prevention system product iWare series has a SQL injection vulnerability. Attackers can use this vulnerability to obtain sensitive database information.

Trust: 0.6

sources: CNVD: CNVD-2020-63989

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-63989

AFFECTED PRODUCTS

vendor:new h3cmodel:secblade ips enhanced copyrightscope:eqversion:2004-2011

Trust: 0.6

vendor:new h3cmodel:secpath t5000s3 copyrightscope:eqversion:2004-2011

Trust: 0.6

vendor:new h3cmodel:secpath t200-a t200-m copyrightscope:eqversion:2004-2011

Trust: 0.6

vendor:new h3cmodel:secblade ips copyrightscope:eqversion:2004-2011

Trust: 0.6

vendor:new h3cmodel:secpath t1000-a t1000-m t1000-s t1000-c copyrightscope:eqversion:2004-2011

Trust: 0.6

vendor:new h3cmodel:secpath t200-s copyrightscope:eqversion:2004-2011

Trust: 0.6

sources: CNVD: CNVD-2020-63989

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-63989
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-63989
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-63989

EXTERNAL IDS

db:CNVDid:CNVD-2020-63989

Trust: 0.6

sources: CNVD: CNVD-2020-63989

SOURCES

db:CNVDid:CNVD-2020-63989

LAST UPDATE DATE

2022-05-04T08:33:51.837000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-63989date:2020-11-18T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-63989date:2020-10-30T00:00:00