CVE-2021-40007
- EPSS 0.15%
- Published 13.12.2021 16:15:09
- Last modified 21.11.2024 06:23:21
There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure.
CVE-2021-39995
- EPSS 0.16%
- Published 29.11.2021 16:15:07
- Last modified 21.11.2024 06:20:42
Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD ...
CVE-2021-37036
- EPSS 0.03%
- Published 23.11.2021 15:15:07
- Last modified 21.11.2024 06:14:32
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the de...
CVE-2021-22396
- EPSS 0.02%
- Published 02.08.2021 17:15:14
- Last modified 21.11.2024 05:50:02
There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escal...
CVE-2021-22383
- EPSS 0.15%
- Published 22.06.2021 19:15:08
- Last modified 21.11.2024 05:50:01
There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability...
CVE-2021-22363
- EPSS 0.18%
- Published 22.06.2021 19:15:07
- Last modified 21.11.2024 05:49:58
There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnera...
CVE-2021-22378
- EPSS 0.14%
- Published 22.06.2021 19:15:07
- Last modified 21.11.2024 05:50:00
There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected devic...
CVE-2021-22300
- EPSS 0.01%
- Published 06.02.2021 01:15:13
- Last modified 21.11.2024 05:49:52
There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process...