HTTP Request Interpretation Flaw in Huawei Products
CVE-2021-22293

7.5HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
6 February 2021

Summary

A vulnerability exists in multiple Huawei products where an inconsistent interpretation of HTTP requests may allow attackers to exploit the system, potentially leading to unauthorized information disclosure. This flaw affects various versions of CampusInsight and ManageOne, as well as specific models in the Taurus-AL00A series. It underscores the importance of ensuring consistent handling of web protocols to mitigate potential security risks.

Affected Version(s)

CampusInsight V100R019C10

ManageOne 6.5.1.1

ManageOne 6.5.1.SPC100

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.