First published: Tue Jun 22 2021(Updated: )
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei S12700 Firmware | =v200r019c00spc500 | |
Huawei S12700 | ||
Huawei S2700 Firmware | =v200r019c00spc500 | |
Huawei S2700 | ||
Huawei S5700 Firmware | =v200r019c00spc500 | |
Huawei S5700 | ||
Huawei S6700 Firmware | =v200r019c00spc500 | |
Huawei S6700 | ||
Huawei S7700 Firmware | =v200r019c00spc500 | |
Huawei S7700 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22377 is a command injection vulnerability in Huawei S12700, S2700, S5700, S6700, and S7700. A module does not verify specific input sufficiently, allowing attackers to exploit this vulnerability.
CVE-2021-22377 has a severity rating of 7.2 (High).
Attackers can exploit CVE-2021-22377 by sending malicious parameter input to the affected devices.
The vulnerable versions of the affected software are: S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500, and S7700 V200R019C00SPC500.
To fix CVE-2021-22377, it is recommended to apply the patches provided by Huawei. Please refer to the official Huawei security advisory for more information.