ZeroHour

CVE-2020-1811

CVSS 3.1
8.8 high
EPSS
1%p65
Published
()
Modified
Description

GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands.

Vendors
huawei
Products
gaussdb 200
Weakness
CWE-20, CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.