// For flags

CVE-2020-9069

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly. Affected product versions include: Anne-AL00 Versions earlier than 9.1.0.331(C675E9R1P3T8); Berkeley-L09 Versions earlier than 10.0.1.1(C675R1); CD16-10 Versions earlier than 10.0.2.8; CD17-10 Versions earlier than 10.0.2.8; CD17-16 Versions earlier than 10.0.2.8; CD18-10 Versions earlier than 10.0.2.8; CD18-16 Versions earlier than 10.0.2.8; Columbia-TL00B Versions earlier than 9.0.0.187(C01E181R1P20T8); E6878-370 Versions earlier than 10.0.5.1(H610SP10C00); HUAWEI P30 lite Versions earlier than 10.0.0.185(C605E3R1P3), Versions earlier than 10.0.0.197(C432E8R2P7); HUAWEI nova 4e Versions earlier than 10.0.0.158(C00E64R1P9); Honor 10 Lite 9.0.1.113(C675E11R1P12); LelandP-L22A Versions earlier than 9.1.0.166(C675E5R1P4T8); Marie-AL00AX Versions earlier than 10.0.0.158(C00E64R1P9); Marie-AL00AY Versions earlier than 10.0.0.158(C00E64R1P9); Marie-AL00BX Versions earlier than 10.0.0.158(C00E64R1P9); Marie-L03BX Versions earlier than 10.0.0.188(C605E5R1P1); Marie-L21BX Versions earlier than 10.0.0.188(C432E4R4P1), Versions earlier than 10.0.0.188(C461E5R3P1); Marie-L22BX Versions earlier than 10.0.0.188(C636E3R3P1); Marie-L23BX Versions earlier than 10.0.0.188(C605E5R1P1); TC5200-16 Versions earlier than 10.0.2.8; WS5200-11 Versions earlier than 10.0.2.8; WS5200-12 Versions earlier than 10.0.2.23; WS5200-16 Versions earlier than 10.0.2.8; WS5200-17 Versions earlier than 10.0.2.23; WS5800-10 Versions earlier than 10.0.3.27; WS6500-10 Versions earlier than 10.0.2.8; WS6500-16 Versions earlier than 10.0.2.8

Hay una vulnerabilidad de filtrado de información en algunos productos Huawei. Un atacante adyacente no autenticado podría explotar esta vulnerabilidad para descifrar datos. Las versiones de producto afectadas incluyen: Anne-AL00 Versiones anteriores a la versión 9.1.0.331(C675E9R1P3T8); Berkeley-L09 Versiones anteriores a la versión 10.0.1.1(C675R1); CD16-10 Versiones anteriores a la versión 10.0.2.8; CD17-10 Versiones anteriores a la versión 10.0.2.8; CD17-16 Versiones anteriores a la versión 10.0.2.8; CD18-10 Versiones anteriores a la versión 10.0.2.8; CD18-16 Versiones anteriores a la versión 10.0.2.8; Columbia-TL00B Versiones anteriores a la versión 9.0.0.187(C01E181R1P20T8); E6878-370 Versiones anteriores a la versión 10.0.2.8; Columbia-TL00B Versiones anteriores a la versión 9.0.0.187(C01E181R1P20T8); E6878-370 Versiones anteriores a la versión 10.0.han 10.0.5.1(H610SP10C00); HUAWEI P30 lite Versiones anteriores a la versión 10.0.0.185(C605E3R1P3), Versiones anteriores a la versión 10.0.0.197(C432E8R2P7); HUAWEI nova 4e Versiones anteriores a la versión 10.0.0.158(C00E64R1P9); Honor 10 Lite 9.0.1.113(C675E11R1P12); LelandP-L22A Versiones anteriores a la versión 9.1.0.166(C675E5R1P4T8); Marie-AL00AX Versiones anteriores a la versión 10.0.0.158(C00E64R1P9); Marie-AL00AY Versiones anteriores a la versión 10.0.0.158(C00E64R1P9); Marie-AL00BX Versiones anteriores a la versión 10.0.0.158(C00E64R1P9); Marie-L03BX Versiones anteriores a la versión 10.0.0.188(C605E5R1P1); Marie-L21BX Versiones anteriores a la versión 10.0.0.188(C432E4R4P1), V 10.0.0.188(C461E5R3P1); Marie-L22BX Versiones anteriores a la versión 10.0.0.188(C636E3R3P1); Marie-L23BX Versiones anteriores a la versión 10.0.0.188(C605E5R1P1); TC5200-16 Versiones anteriores a la versión 10.0.2.8; WS5200-11 Versiones anteriores a la versión 10.0.2.8; WS5200-12 Versiones anteriores a la versión 10.0.2.23; WS5200-16 Versiones anteriores a la versión 10.0.2.8; WS5200-17 Versiones anteriores a la versión 10.0.2.23; WS5800-10 Versiones anteriores a la versión 10.0.3.27; WS6500-10 Versiones anteriores a la versión 10.0.2.8; WS6500-16 Versiones anteriores a la versión 10.0.2.8

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-02-18 CVE Reserved
  • 2020-05-21 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
Anne-al00 Firmware
Search vendor "Huawei" for product "Anne-al00 Firmware"
< 9.1.0.331\(c675e9r1p3t8\)
Search vendor "Huawei" for product "Anne-al00 Firmware" and version " < 9.1.0.331\(c675e9r1p3t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
Anne-al00
Search vendor "Huawei" for product "Anne-al00"
--
Safe
Huawei
Search vendor "Huawei"
Berkeley-l09 Firmware
Search vendor "Huawei" for product "Berkeley-l09 Firmware"
< 10.0.1.1\(c675r1\)
Search vendor "Huawei" for product "Berkeley-l09 Firmware" and version " < 10.0.1.1\(c675r1\)"
-
Affected
in Huawei
Search vendor "Huawei"
Berkeley-l09
Search vendor "Huawei" for product "Berkeley-l09"
--
Safe
Huawei
Search vendor "Huawei"
Cd16-10 Firmware
Search vendor "Huawei" for product "Cd16-10 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Cd16-10 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Cd16-10
Search vendor "Huawei" for product "Cd16-10"
--
Safe
Huawei
Search vendor "Huawei"
Cd17-10 Firmware
Search vendor "Huawei" for product "Cd17-10 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Cd17-10 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Cd17-10
Search vendor "Huawei" for product "Cd17-10"
--
Safe
Huawei
Search vendor "Huawei"
Cd17-16 Firmware
Search vendor "Huawei" for product "Cd17-16 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Cd17-16 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Cd17-16
Search vendor "Huawei" for product "Cd17-16"
--
Safe
Huawei
Search vendor "Huawei"
Cd18-10 Firmware
Search vendor "Huawei" for product "Cd18-10 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Cd18-10 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Cd18-10
Search vendor "Huawei" for product "Cd18-10"
--
Safe
Huawei
Search vendor "Huawei"
Cd18-16 Firmware
Search vendor "Huawei" for product "Cd18-16 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Cd18-16 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Cd18-16
Search vendor "Huawei" for product "Cd18-16"
--
Safe
Huawei
Search vendor "Huawei"
Columbia-tl00b Firmware
Search vendor "Huawei" for product "Columbia-tl00b Firmware"
< 9.0.0.187\(c01e181r1p20t8\)
Search vendor "Huawei" for product "Columbia-tl00b Firmware" and version " < 9.0.0.187\(c01e181r1p20t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
Columbia-tl00b
Search vendor "Huawei" for product "Columbia-tl00b"
--
Safe
Huawei
Search vendor "Huawei"
E6878-370 Firmware
Search vendor "Huawei" for product "E6878-370 Firmware"
< 10.0.5.1\(h610sp10c00\)
Search vendor "Huawei" for product "E6878-370 Firmware" and version " < 10.0.5.1\(h610sp10c00\)"
-
Affected
in Huawei
Search vendor "Huawei"
E6878-370
Search vendor "Huawei" for product "E6878-370"
--
Safe
Huawei
Search vendor "Huawei"
Honor 10 Lite Firmware
Search vendor "Huawei" for product "Honor 10 Lite Firmware"
< 10.0.0.182\(c675e17r2p2\)
Search vendor "Huawei" for product "Honor 10 Lite Firmware" and version " < 10.0.0.182\(c675e17r2p2\)"
-
Affected
in Huawei
Search vendor "Huawei"
Honor 10 Lite
Search vendor "Huawei" for product "Honor 10 Lite"
--
Safe
Huawei
Search vendor "Huawei"
Lelandp-l22a Firmware
Search vendor "Huawei" for product "Lelandp-l22a Firmware"
< 9.1.0.166\(c675e5r1p4t8\)
Search vendor "Huawei" for product "Lelandp-l22a Firmware" and version " < 9.1.0.166\(c675e5r1p4t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
Lelandp-l22a
Search vendor "Huawei" for product "Lelandp-l22a"
--
Safe
Huawei
Search vendor "Huawei"
Tc5200-16 Firmware
Search vendor "Huawei" for product "Tc5200-16 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Tc5200-16 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Tc5200-16
Search vendor "Huawei" for product "Tc5200-16"
--
Safe
Huawei
Search vendor "Huawei"
Ws5200-11 Firmware
Search vendor "Huawei" for product "Ws5200-11 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Ws5200-11 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Ws5200-11
Search vendor "Huawei" for product "Ws5200-11"
--
Safe
Huawei
Search vendor "Huawei"
Ws5200-11 Firmware
Search vendor "Huawei" for product "Ws5200-11 Firmware"
< 10.0.2.23
Search vendor "Huawei" for product "Ws5200-11 Firmware" and version " < 10.0.2.23"
-
Affected
in Huawei
Search vendor "Huawei"
Ws5200-11
Search vendor "Huawei" for product "Ws5200-11"
--
Safe
Huawei
Search vendor "Huawei"
Ws5200-16 Firmware
Search vendor "Huawei" for product "Ws5200-16 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Ws5200-16 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Ws5200-16
Search vendor "Huawei" for product "Ws5200-16"
--
Safe
Huawei
Search vendor "Huawei"
Ws5200-17 Firmware
Search vendor "Huawei" for product "Ws5200-17 Firmware"
< 10.0.2.23
Search vendor "Huawei" for product "Ws5200-17 Firmware" and version " < 10.0.2.23"
-
Affected
in Huawei
Search vendor "Huawei"
Ws5200-17
Search vendor "Huawei" for product "Ws5200-17"
--
Safe
Huawei
Search vendor "Huawei"
Ws5800-10 Firmware
Search vendor "Huawei" for product "Ws5800-10 Firmware"
< 10.0.3.27
Search vendor "Huawei" for product "Ws5800-10 Firmware" and version " < 10.0.3.27"
-
Affected
in Huawei
Search vendor "Huawei"
Ws5800-10
Search vendor "Huawei" for product "Ws5800-10"
--
Safe
Huawei
Search vendor "Huawei"
Ws6500-10 Firmware
Search vendor "Huawei" for product "Ws6500-10 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Ws6500-10 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Ws6500-10
Search vendor "Huawei" for product "Ws6500-10"
--
Safe
Huawei
Search vendor "Huawei"
Ws6500-16 Firmware
Search vendor "Huawei" for product "Ws6500-16 Firmware"
< 10.0.2.8
Search vendor "Huawei" for product "Ws6500-16 Firmware" and version " < 10.0.2.8"
-
Affected
in Huawei
Search vendor "Huawei"
Ws6500-16
Search vendor "Huawei" for product "Ws6500-16"
--
Safe