Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20210203-01-PLAINTEXTLOG
HistoryFeb 03, 2021 - 12:00 a.m.

Security Advisory - Information Leakage Vulnerability in Some Huawei Products

2021-02-0300:00:00
Huawei Technologies
www.huawei.com
23

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak. (Vulnerability ID: HWPSIRT-2020-01916)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2021-22310.
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:
<http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-plaintextlog-en&gt;

Affected configurations

Vulners
Node
huaweinip6300Matchv500r001c00
OR
huaweinip6300Matchv500r001c20
OR
huaweinip6300Matchv500r001c30
OR
huaweinip6600Matchv500r001c00
OR
huaweinip6600Matchv500r001c20
OR
huaweinip6600Matchv500r001c30
OR
huaweisecospace_usg6300Matchv500r001c00
OR
huaweisecospace_usg6300Matchv500r001c20
OR
huaweisecospace_usg6300Matchv500r001c30
OR
huaweisecospace_usg6500Matchv500r001c00
OR
huaweisecospace_usg6500Matchv500r001c20
OR
huaweisecospace_usg6500Matchv500r001c30
OR
huaweisecospace_usg6600Matchv500r001c00
OR
huaweisecospace_usg6600Matchv500r001c20
OR
huaweisecospace_usg6600Matchv500r001c30
OR
huaweisecospace_usg6600Matchv500r001c50
OR
huaweisecospace_usg6600Matchv500r001c60
OR
huaweisecospace_usg6600Matchv500r001c80
OR
huaweiusg9500Matchv500r005c00
OR
huaweiusg9500Matchv500r005c10

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

Related for HUAWEI-SA-20210203-01-PLAINTEXTLOG