Information disclosure in Huawei products - CVE-2021-22342
Published: June 4, 2021
Vulnerability identifier: #VU53790
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22342
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote administrator can gain unauthorized access to sensitive information on the system.
Affected software
USG9500
Huawei IPS Module
Huawei NGFW Module
Huawei SeMG9811
Huawei IPS Module
Huawei NGFW Module
Huawei SeMG9811
How to mitigate CVE-2021-22342
Install updates from vendor's website.
USG9500 - update to V500R005C20SPC500+V500R005SPH008
Huawei IPS Module - update to V500R005C20SPC500+V500R005SPH008
Huawei NGFW Module - update to V500R005C20SPC500+V500R005SPH008
Huawei SeMG9811 - update to V500R005C00SPC200+V500R005SPH008
Huawei IPS Module - update to V500R005C20SPC500+V500R005SPH008
Huawei NGFW Module - update to V500R005C20SPC500+V500R005SPH008
Huawei SeMG9811 - update to V500R005C00SPC200+V500R005SPH008