CVE-2020-9084
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
18/09/2020
Last modified:
29/09/2020
Description
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:taurus-an00b_firmware:*:*:*:*:*:*:*:* | 10.1.0.156\(c00e155r7p2\) (excluding) | |
| cpe:2.3:h:huawei:taurus-an00b:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



