There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V500R005C00,V500R005C10, V500R005C20; SeMG9811 versions V500R005C00; USG9500 versions V500R001C00, V500R001C20, V500R001C30, V500R001C50, V500R001C60, V500R001C80, V500R005C00, V500R005C10, V500R005C20.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-infomationleak-en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
29 Jun 2021, 16:56
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 | |
References | (MISC) https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-infomationleak-en - Vendor Advisory | |
CPE | cpe:2.3:o:huawei:ips_module_firmware:v500r005c10:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c60:*:*:*:*:*:*:* cpe:2.3:h:huawei:semg9811:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r005c10:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c80:*:*:*:*:*:*:* cpe:2.3:h:huawei:ngfw_module:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r005c10:*:*:*:*:*:*:* cpe:2.3:h:huawei:ips_module:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r005c20:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c50:*:*:*:*:*:*:* cpe:2.3:o:huawei:ngfw_module_firmware:v500r005c20:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c30:*:*:*:*:*:*:* cpe:2.3:h:huawei:usg9500:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r005c20:*:*:*:*:*:*:* cpe:2.3:o:huawei:ips_module_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:semg9811_firmware:v500r005c00:*:*:*:*:*:*:* cpe:2.3:o:huawei:usg9500_firmware:v500r001c20:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 4.9 |
22 Jun 2021, 19:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-22 19:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-22342
Mitre link : CVE-2021-22342
CVE.ORG link : CVE-2021-22342
JSON object : View
Products Affected
huawei
- usg9500_firmware
- ngfw_module_firmware
- ips_module
- usg9500
- ips_module_firmware
- semg9811
- semg9811_firmware
- ngfw_module
CWE