Memory leak in Huawei products - CVE-2021-22312

 

Memory leak in Huawei products - CVE-2021-22312

Published: February 11, 2021


Vulnerability identifier: #VU50647
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22312
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak. A remote authenticated attacker can force the application to leak memory and perform denial of service attack.


Affected software

Huawei Secospace USG6500
Huawei Secospace USG6600
Huawei Secospace USG6300
USG9500
Huawei NGFW Module
Huawei IPS Module

How to mitigate CVE-2021-22312

Install updates from vendor's website.

Huawei Secospace USG6500 - update to V500R005C20SPC500
USG9500 - update to V500R005C20SCP500
Huawei Secospace USG6600 - update to V500R005C20SPC500
Huawei Secospace USG6300 - update to V500R005C20SPC500
Huawei NGFW Module - update to V500R005SPH008
Huawei IPS Module - update to V500R005SPH008

External References

Related Security Bulletins