Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20220112-01-INFODIS
HistoryJan 19, 2022 - 12:00 a.m.

Security Advisory - Information Exposure Vulnerability on Several Huawei Products

2022-01-1900:00:00
Huawei Technologies
www.huawei.com
19

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software does not properly protect certain information. Successful exploit could cause information disclosure. (Vulnerability ID: HWPSIRT-2020-32928) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2021-40033. This vulnerability was discovered by Huawei internal tester. For products that have released software updates to fix this vulnerability, Huawei will release and update the Security Advisory at: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220112-01-infodis-en

Affected configurations

Vulners
Node
huaweicloudengine_12800_firmwareMatchv200r005c10spc800
OR
huaweicloudengine_5800Matchv200r005c10spc800
OR
huaweicloudengine_5800Matchv200r019c00spc800
OR
huaweicloudengine_6800_firmwareMatchv200r005c10spc800
OR
huaweicloudengine_6800_firmwareMatchv200r005c20spc800
OR
huaweicloudengine_6800_firmwareMatchv200r019c00spc800
OR
huaweicloudengine_7800_firmwareMatchv200r005c10spc800
OR
huaweicloudengine_7800_firmwareMatchv200r019c00spc800

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

12.6%

Related for HUAWEI-SA-20220112-01-INFODIS