Input validation error in Huawei products - CVE-2021-22393
Published: March 29, 2021
Vulnerability identifier: #VU51749
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22393
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to module design weakness. A remote attacker on the local network can send a large amount of specific messages and perform a denial of service (DoS) attack.
Affected software
Huawei CloudEngine 12800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
How to mitigate CVE-2021-22393
Install updates from vendor's website.
Huawei CloudEngine 12800 - update to V200R005C10SPC800+V200R005SPH026
Huawei CloudEngine 5800 - update to V200R005C10SPC800+V200R005SPH025
Huawei CloudEngine 6800 - update to V200R005C10SPC800+V200R005SPH026
Huawei CloudEngine 7800 - update to V200R005C10SPC800+V200R005SPH026
Huawei CloudEngine 5800 - update to V200R005C10SPC800+V200R005SPH025
Huawei CloudEngine 6800 - update to V200R005C10SPC800+V200R005SPH026
Huawei CloudEngine 7800 - update to V200R005C10SPC800+V200R005SPH026