CVE-2021-22342
4.9
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.2 / Impact: 3.6
Source: NVD
Description
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V500R005C00,V500R005C10, V500R005C20; SeMG9811 versions V500R005C00; USG9500 versions V500R001C00, V500R001C20, V500R001C30, V500R001C50, V500R001C60, V500R001C80, V500R005C00, V500R005C10, V500R005C20.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ips Module | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ngfw Module | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Semg9811 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Usg9500 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.