ID

VAR-202106-0589


CVE

CVE-2021-22365


TITLE

eSE620X vESS  Out-of-bounds read vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2021-008568

DESCRIPTION

There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful exploit may cause the process and the service abnormal. eSE620X vESS Is vulnerable to an out-of-bounds read.Denial of service (DoS) It may be put into a state. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements

Trust: 2.16

sources: NVD: CVE-2021-22365 // JVNDB: JVNDB-2021-008568 // CNNVD: CNNVD-202104-975

AFFECTED PRODUCTS

vendor:huaweimodel:ese620x vessscope:eqversion:v100r001c10spc200

Trust: 1.0

vendor:huaweimodel:ese620x vessscope:eqversion:v100r001c20spc200

Trust: 1.0

vendor:huaweimodel:ese620x vessscope:eqversion:v200r001c00spc300

Trust: 1.0

vendor:huaweimodel:ese620x vessscope:eqversion:ese620x vess firmware v100r001c10spc200

Trust: 0.8

vendor:huaweimodel:ese620x vessscope:eqversion: -

Trust: 0.8

vendor:huaweimodel:ese620x vessscope:eqversion:ese620x vess firmware v100r001c20spc200

Trust: 0.8

vendor:huaweimodel:ese620x vessscope:eqversion:ese620x vess firmware v200r001c00spc300

Trust: 0.8

sources: JVNDB: JVNDB-2021-008568 // NVD: CVE-2021-22365

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22365
value: LOW

Trust: 1.0

NVD: CVE-2021-22365
value: LOW

Trust: 0.8

CNNVD: CNNVD-202104-975
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202105-1770
value: LOW

Trust: 0.6

nvd@nist.gov: CVE-2021-22365
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-22365
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 1.8
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: CVE-2021-22365
baseSeverity: LOW
baseScore: 3.3
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-008568 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1770 // NVD: CVE-2021-22365

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.0

problemtype:Out-of-bounds read (CWE-125) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-008568 // NVD: CVE-2021-22365

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202105-1770

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

PATCH

title:huawei-sa-20210526-02-outboundsurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210526-02-outbounds-en

Trust: 0.8

title:Huawei ESE620X vESS Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=155519

Trust: 0.6

sources: JVNDB: JVNDB-2021-008568 // CNNVD: CNNVD-202105-1770

EXTERNAL IDS

db:NVDid:CVE-2021-22365

Trust: 3.2

db:JVNDBid:JVNDB-2021-008568

Trust: 0.8

db:CS-HELPid:SB2021041363

Trust: 0.6

db:CNNVDid:CNNVD-202104-975

Trust: 0.6

db:CS-HELPid:SB2021052703

Trust: 0.6

db:CNNVDid:CNNVD-202105-1770

Trust: 0.6

sources: JVNDB: JVNDB-2021-008568 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1770 // NVD: CVE-2021-22365

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210526-02-outbounds-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-22365

Trust: 0.8

url:https://www.cybersecurity-help.cz/vdb/sb2021041363

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210526-02-outbounds-cn

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021052703

Trust: 0.6

sources: JVNDB: JVNDB-2021-008568 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1770 // NVD: CVE-2021-22365

SOURCES

db:JVNDBid:JVNDB-2021-008568
db:CNNVDid:CNNVD-202104-975
db:CNNVDid:CNNVD-202105-1770
db:NVDid:CVE-2021-22365

LAST UPDATE DATE

2024-08-14T12:11:34.608000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2021-008568date:2022-03-18T09:13:00
db:CNNVDid:CNNVD-202104-975date:2021-04-14T00:00:00
db:CNNVDid:CNNVD-202105-1770date:2021-06-30T00:00:00
db:NVDid:CVE-2021-22365date:2021-06-29T15:35:28.217

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2021-008568date:2022-03-18T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-13T00:00:00
db:CNNVDid:CNNVD-202105-1770date:2021-05-26T00:00:00
db:NVDid:CVE-2021-22365date:2021-06-22T18:15:08.003