First published: Tue Nov 23 2021(Updated: )
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Ecns280 Td Firmware | =v100r005c00 | |
Huawei Ecns280 Td Firmware | =v100r005c10 | |
Huawei Ecns280 Td | ||
Huawei FusionCompute | =6.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37036.
The severity of CVE-2021-37036 is medium with a CVSS score of 5.5.
FusionCompute 6.5.1, eCNS280_TD V100R005C00, and V100R005C10 are affected by CVE-2021-37036.
An attacker can exploit CVE-2021-37036 by obtaining specific information stored in the log file when a user logs in to the device.
Please refer to the official security advisory by Huawei for information on the fix for CVE-2021-37036: [link](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210818-01-informationleak-en)