4.4
CVE-2021-22310
- EPSS 0.03%
- Veröffentlicht 22.03.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 05:49:53
- Quelle psirt@huawei.com
- CVE-Watchlists
- Unerledigt
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions V500R001C00,V500R001C20,V500R001C30;NIP6600 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6300 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6500 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6600 versions V500R001C00,V500R001C20,V500R001C30,V500R001C50,V500R001C60,V500R001C80;USG9500 versions V500R005C00,V500R005C10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Nip6300 Firmware Versionv500r001c00
Huawei ≫ Nip6300 Firmware Versionv500r001c20
Huawei ≫ Nip6300 Firmware Versionv500r001c30
Huawei ≫ Nip6600 Firmware Versionv500r001c00
Huawei ≫ Nip6600 Firmware Versionv500r001c20
Huawei ≫ Nip6600 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6300 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6500 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c00
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c20
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c30
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c50
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c60
Huawei ≫ Secospace Usg6600 Firmware Versionv500r001c80
Huawei ≫ Usg9500 Firmware Versionv500r005c00
Huawei ≫ Usg9500 Firmware Versionv500r005c10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.044 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.