CVE-2021-22365

There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful exploit may cause the process and the service abnormal.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:ese620x_vess_firmware:v100r001c10spc200:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ese620x_vess_firmware:v100r001c20spc200:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ese620x_vess_firmware:v200r001c00spc300:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ese620x_vess:-:*:*:*:*:*:*:*

History

29 Jun 2021, 15:35

Type Values Removed Values Added
CPE cpe:2.3:h:huawei:ese620x_vess:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ese620x_vess_firmware:v200r001c00spc300:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ese620x_vess_firmware:v100r001c10spc200:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ese620x_vess_firmware:v100r001c20spc200:*:*:*:*:*:*:*
CWE CWE-125
References (MISC) https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210526-02-outbounds-en - (MISC) https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210526-02-outbounds-en - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 3.3

22 Jun 2021, 19:08

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-22 18:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-22365

Mitre link : CVE-2021-22365

CVE.ORG link : CVE-2021-22365


JSON object : View

Products Affected

huawei

  • ese620x_vess
  • ese620x_vess_firmware
CWE
CWE-125

Out-of-bounds Read