CVE-2021-22361

Severity
7.8HIGH
EPSS
0.0%
top 92.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 24

Description

There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may compromise the normal service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDhuawei/ese620x_vess_firmwarev100r001c10spc200, v100r001c20spc200+1
NVDhuawei/ecns280_firmwarev100r005c00, v100r005c10+1

🔴Vulnerability Details

2
GHSA
GHSA-2mqr-75c4-43q9: There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC2002022-05-24
CVEList
CVE-2021-22361: There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC2002021-06-22
CVE-2021-22361 (HIGH CVSS 7.8) | There is an improper authorization | cvebase.io