CVE-2021-37036: Medium severity huawei ecns280 vulnerability
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information leakage vulnerability?
The vulnerability ID is CVE-2021-37036.
What is the severity of CVE-2021-37036?
The severity of CVE-2021-37036 is medium with a CVSS score of 5.5.
Which software and versions are affected by CVE-2021-37036?
FusionCompute 6.5.1, eCNS280_TD V100R005C00, and V100R005C10 are affected by CVE-2021-37036.
How can an attacker exploit CVE-2021-37036?
An attacker can exploit CVE-2021-37036 by obtaining specific information stored in the log file when a user logs in to the device.
Is there a fix available for CVE-2021-37036?
Please refer to the official security advisory by Huawei for information on the fix for CVE-2021-37036: [link](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210818-01-informationleak-en)