First published: Wed Apr 28 2021(Updated: )
There is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. The affected product cannot deal with some messages because of module design weakness . Attackers can exploit this vulnerability by sending a large amount of specific messages to cause denial of service. This can compromise normal service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 12800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r005c10spc800 | |
Huawei CloudEngine 12800 | ||
Huawei CloudEngine 5800 | =v200r002c50spc800 | |
Huawei CloudEngine 5800 | =v200r003c00spc810 | |
Huawei CloudEngine 5800 | =v200r005c00spc800 | |
Huawei CloudEngine 5800 | =v200r005c10spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 6800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c10spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r002c50spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r003c00spc810 | |
Huawei Cloudengine 7800 Firmware | =v200r005c00spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22393 is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800, and CloudEngine 12800.
Attackers can exploit the CVE-2021-22393 vulnerability by sending a large amount of specific messages to the affected product, which cannot handle them properly due to a module design weakness.
CVE-2021-22393 has a severity rating of 7.5, which is considered high.
The vulnerability affects versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800, and CloudEngine 12800.
To fix the CVE-2021-22393 vulnerability, it is recommended to update to a version of the affected product that is not vulnerable. Check the vendor's security advisory for specific patch information.