CVE-2021-22310

4.4MEDIUM

Key Information:

Summary

There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions V500R001C00,V500R001C20,V500R001C30;NIP6600 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6300 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6500 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6600 versions V500R001C00,V500R001C20,V500R001C30,V500R001C50,V500R001C60,V500R001C80;USG9500 versions V500R005C00,V500R005C10.

Affected Version(s)

NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 V500R001C00,V500R001C20,V500R001C30

NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 V500R001C00,V500R001C20,V500R001C30,V500R001C50,V500R001C60,V500R001C80

NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 V500R005C00,V500R005C10

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.