Race Condition Vulnerability in eCNS280_TD by Huawei
CVE-2021-22378
5.3MEDIUM
Summary
The eCNS280_TD product from Huawei is susceptible to a race condition vulnerability that can occur during concurrent database operations. This vulnerability arises from a timing window where a secondary thread may gain access to the database while it is being manipulated, potentially leading to abnormal behavior of the device. If successfully exploited, this may disrupt normal operations, impacting the reliability of services dependent on the affected versions.
Affected Version(s)
eCNS280_TD V100R005C00
eCNS280_TD V100R005C10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved