cbcvebase.
CVE-2021-22342
published 2021-06-22

CVE-2021-22342: There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit…

PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.56%
43.0th percentile
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V500R005C00,V500R005C10, V500R005C20; SeMG9811 versions V500R005C00; USG9500 versions V500R001C00, V500R001C20, V500R001C30, V500R001C50, V500R001C60, V500R001C80, V500R005C00, V500R005C10, V500R005C20.

Affected

16 ranges
VendorProductVersion rangeFixed in
huaweiips_module_firmware
huaweiips_module_firmware
huaweiips_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweingfw_module_firmware
huaweisemg9811_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware
huaweiusg9500_firmware

CVSS provenance

nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.