First published: Tue Jun 22 2021(Updated: )
There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit this vulnerability by sending a specific message to the target device, which could cause a Denial of Service (DoS).
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei ECNS280 | =v100r005c10 | |
Huawei ECNS280 | ||
Huawei Ese620x Vess | =v100r001c10spc200 | |
Huawei Ese620x Vess | =v100r001c20spc200 | |
Huawei Ese620x Vess | =v200r001c00spc300 | |
Huawei Ese620x Vess Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22383 is classified as a high-severity vulnerability due to the potential for an attacker to exploit it for unauthorized access.
To fix CVE-2021-22383, users should update their affected Huawei eCNS280_TD and eSE620X VESS firmware to the latest patched versions.
CVE-2021-22383 affects Huawei eCNS280_TD V100R005C10 and eSE620X VESS firmware versions V100R001C10SPC200, V100R001C20SPC200, and V200R001C00SPC300.
CVE-2021-22383 is an out-of-bounds read vulnerability found in a message-handling function.
Yes, an attacker can potentially exploit CVE-2021-22383 remotely due to the nature of the vulnerability in the message-handling function.