XXE Injection Vulnerability in eCNS280 by Huawei
CVE-2021-22338
5.3MEDIUM
What is CVE-2021-22338?
An XXE injection vulnerability exists in Huawei's eCNS280 product versions V100R005C00 and V100R005C10. This vulnerability arises from the failure to validate input XML messages adequately, allowing attackers to craft specific XML messages that can exploit the vulnerability. Successfully exploiting this flaw could lead to a denial of service for the affected module, resulting in potential disruption of services.
Affected Version(s)
eCNS280 V100R005C00,V100R005C10