CVE-2021-22338: XEE
Published Jun 29, 2021
·Updated
There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.
Affected Software
3 affected components
huawei Ecns280 Firmware=v100r005c00
huawei Ecns280 Firmware=v100r005c10
huawei Ecns280
Event History
Jun 29, 2021
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22338?
CVE-2021-22338 is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10.
2
How severe is CVE-2021-22338?
CVE-2021-22338 has a severity rating of 5.3 (medium).
3
What is the affected software version for CVE-2021-22338?
The affected software versions for CVE-2021-22338 are eCNS280 V100R005C00 and V100R005C10.
4
How can an attacker exploit CVE-2021-22338?
An attacker can exploit CVE-2021-22338 by sending a specific message to the module, leading to denial of service.
5
Is there a fix available for CVE-2021-22338?
To fix CVE-2021-22338, users should apply the necessary patches or updates provided by Huawei.