Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2021-37036
Disclosure Date: November 23, 2021 (last updated February 23, 2025)
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.
0
Attacker Value
Unknown
CVE-2021-22396
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200.
0
Attacker Value
Unknown
CVE-2021-22338
Disclosure Date: June 29, 2021 (last updated February 22, 2025)
There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.
0
Attacker Value
Unknown
CVE-2021-22378
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected device abnormal.
0
Attacker Value
Unknown
CVE-2021-22361
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.
0
Attacker Value
Unknown
CVE-2021-22292
Disclosure Date: February 06, 2021 (last updated November 28, 2024)
There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.
0
Attacker Value
Unknown
CVE-2021-22300
Disclosure Date: February 06, 2021 (last updated February 22, 2025)
There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.
0