CVE-2021-22300: Medium severity huawei ecns280 vulnerability
Published Feb 6, 2021
·Updated
There is an information leak vulnerability in eCNS280TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.
Affected Software
3 affected components
Huawei Ecns280 Td Firmware=v100r005c00
Huawei Ecns280 Td Firmware=v100r005c10
Huawei Ecns280 Td
Event History
Feb 6, 2021
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this information leak vulnerability?
The vulnerability ID for this information leak vulnerability is CVE-2021-22300.
2
What is the affected software version of eCNS280_TD?
The affected software versions of eCNS280_TD are V100R005C00 and V100R005C10.
3
What is the severity rating of CVE-2021-22300?
The severity rating of CVE-2021-22300 is medium (4.1).
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by obtaining sensitive information through inter-process access that requires other methods.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Huawei PSIRT security advisories page.