Race Condition Vulnerability in eCNS280_TD by Huawei
CVE-2021-22378

5.3MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
22 June 2021

Summary

The eCNS280_TD product from Huawei is susceptible to a race condition vulnerability that can occur during concurrent database operations. This vulnerability arises from a timing window where a secondary thread may gain access to the database while it is being manipulated, potentially leading to abnormal behavior of the device. If successfully exploited, this may disrupt normal operations, impacting the reliability of services dependent on the affected versions.

Affected Version(s)

eCNS280_TD V100R005C00

eCNS280_TD V100R005C10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.