CVE-2020-9222

HIGH

Huawei FusionCompute - Privilege Escalation via Deserialization

Title source: llm
STIX 2.1

Description

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9222.

References (1)

Core 1

Scores

CVSS v3 7.0
EPSS 0.0004
EPSS Percentile 14.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (5)
huawei/fusioncompute 6.3.0
huawei/fusioncompute 6.3.1
huawei/fusioncompute 6.5.0
huawei/fusioncompute 6.5.1
huawei/fusioncompute 8.0.0
Published Dec 27, 2024
Tracked Since Feb 18, 2026