Fusionaccess
Vendor:
First CVE: Sep 7, 2016 · Active for 9 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fusionaccess over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2016
9 years ago
Most Recent CVE
Oct 12, 2020
2,111 days ago
CVE Severity & Scoring
Fusionaccess5 CVEs
60%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9090HIGH FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to | Oct 12, 2020 | 7.8 | 24 | NO | NO |
CVE-2015-7844HIGH Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protocol packet to cause the virtual cloud desktop to be displayin | Apr 2, 2017 | 7.5 | 19 | NO | NO |
CVE-2020-1825MEDIUM FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vu | Jun 15, 2020 | 6.5 | 17 | NO | NO |
CVE-2016-8779MEDIUM Huawei FusionAccess with software V100R005C10 and V100R005C20 could allow remote attackers with specific permission to inject a Lightweight Directory Access Protocol (LDAP) operati | Apr 2, 2017 | 6.5 | 17 | NO | NO |
CVE-2016-6839MEDIUM CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unsp | Sep 7, 2016 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Fusionaccess
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v100r005c30 | 1 | 6.1 | 0.8% | 0 | 0 |
| v100r005c20 | 3 | 6.7 | 0.8% | 0 | 0 |
| v100r005c10 | 3 | 6.7 | 0.8% | 0 | 0 |
| 6.5.1 | 1 | 7.8 | 0.2% | 0 | 0 |