CVE-2021-22378: Race Condition
Published Jun 22, 2021
·Updated
There is a race condition vulnerability in eCNS280TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected device abnormal.
Affected Software
3 affected components
Huawei Ecns280 Td Firmware=v100r005c00
Huawei Ecns280 Td Firmware=v100r005c10
Huawei Ecns280 Td
Event History
Jun 22, 2021
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this race condition vulnerability?
The vulnerability ID is CVE-2021-22378.
2
What software versions are affected by this vulnerability?
The affected software versions are eCNS280_TD V100R005C00 and V100R005C10.
3
What is the severity of CVE-2021-22378?
The severity of CVE-2021-22378 is medium with a CVSS score of 5.3.
4
What is the impact of this vulnerability?
Successful exploitation of this vulnerability may cause the affected device to behave abnormally.
5
Is there a fix available for this vulnerability?
The vendor has provided a security advisory with mitigation steps. Please refer to the reference link for more information.