CVE-2020-9137

MEDIUM

Huawei CloudEngine 12800, 5800, 6800, and 7800 Firmware - Privilege Escalation via Insufficient Input Validation

Title source: llm
STIX 2.1

Description

There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with high privilege may execute some specially crafted scripts in the affected products. Successful exploit will cause privilege escalation.

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (25)
huawei/cloudengine_12800_firmware v200r002c50spc800
huawei/cloudengine_12800_firmware v200r003c00spc810
huawei/cloudengine_12800_firmware v200r005c00spc800
huawei/cloudengine_12800_firmware v200r005c10spc800
huawei/cloudengine_12800_firmware v200r019c00spc800
huawei/cloudengine_12800_firmware v200r019c10spc800
huawei/cloudengine_5800_firmware v200r002c50spc800
huawei/cloudengine_5800_firmware v200r003c00spc810
huawei/cloudengine_5800_firmware v200r005c00spc800
huawei/cloudengine_5800_firmware v200r005c10spc800
... and 15 more
Published Dec 24, 2020
Tracked Since Feb 18, 2026