CVE-2020-9072

MEDIUM

Huawei OSD Firmware < OSD_uwp_9.0.32.0 - Authenticated Local Privilege Escalation via File Path Manipulation

Title source: llm
STIX 2.1

Description

Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability. An authenticated, local attacker can constructs a specific file path to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 6.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
huawei/osd_firmware < osd_uwp_9.0.32.0
Published Apr 27, 2020
Tracked Since Feb 18, 2026