cbcvebase.
CVE-2021-22341
published 2021-06-29

CVE-2021-22341: There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this…

PriorityP422medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.59%
44.2th percentile
There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R005C00SPC200;NGFW Module V500R005C00SPC100,V500R005C00SPC200;NIP6300 V500R005C00SPC100,V500R005C10SPC200;NIP6600 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6500 V500R005C00SPC100,V500R005C10SPC200;Secospace USG6600 V500R005C00SPC100,V500R005C00SPC200.

Affected

14 ranges
VendorProductVersion rangeFixed in
huaweiips_module_firmware
huaweiips_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweinip6300_firmware
huaweinip6300_firmware
huaweinip6600_firmware
huaweinip6600_firmware
huaweisecospace_usg6300_firmware
huaweisecospace_usg6300_firmware
huaweisecospace_usg6500_firmware
huaweisecospace_usg6500_firmware
huaweisecospace_usg6600_firmware
huaweisecospace_usg6600_firmware

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.