Buffer overflow in Huawei products - CVE-2021-22362
Published: May 19, 2021
Vulnerability identifier: #VU53361
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22362
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A remote attacker on the local network can send a specially crafted packet, trigger memory corruption and cause a denial of service condition on the target system.
Affected software
Huawei CloudEngine 7800
Huawei CloudEngine 6800
Huawei CloudEngine 5800
Huawei CloudEngine 12800
Huawei CloudEngine 6800
Huawei CloudEngine 5800
Huawei CloudEngine 12800
How to mitigate CVE-2021-22362
Install updates from vendor's website.
Huawei CloudEngine 7800 - addressed in versions V200R005C10SPC800+V200R005SPH026, V200R019C10SPC800+V200R019SPH006
Huawei CloudEngine 12800 - addressed in versions V200R005C10SPC800 + V200R005SPH026, V200R019C10SPC800 + V200R019SPH006
Huawei CloudEngine 6800 - addressed in versions V200R005C10SPC800 + V200R005SPH026, V200R019C10SPC800 + V200R019SPH006
Huawei CloudEngine 5800 - addressed in versions V200R005C10SPC800 + V200R005SPH025, V200R019C10SPC800 + V200R019SPH006
Huawei CloudEngine 12800 - addressed in versions V200R005C10SPC800 + V200R005SPH026, V200R019C10SPC800 + V200R019SPH006
Huawei CloudEngine 6800 - addressed in versions V200R005C10SPC800 + V200R005SPH026, V200R019C10SPC800 + V200R019SPH006
Huawei CloudEngine 5800 - addressed in versions V200R005C10SPC800 + V200R005SPH025, V200R019C10SPC800 + V200R019SPH006