XXE Injection Vulnerability in eCNS280 by Huawei
CVE-2021-22338

5.3MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
29 June 2021

Summary

An XXE injection vulnerability exists in Huawei's eCNS280 product versions V100R005C00 and V100R005C10. This vulnerability arises from the failure to validate input XML messages adequately, allowing attackers to craft specific XML messages that can exploit the vulnerability. Successfully exploiting this flaw could lead to a denial of service for the affected module, resulting in potential disruption of services.

Affected Version(s)

eCNS280 V100R005C00,V100R005C10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.