ID

VAR-202106-0620


CVE

CVE-2021-22338


TITLE

eCNS280 code issue vulnerability

Trust: 0.6

sources: CNVD: CNVD-2021-55171

DESCRIPTION

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service. Huawei eCNS280 is the core network equipment of China's Huawei (Huawei) wireless broadband trunking system. In addition to providing the network functions of the traditional core network, it also provides capacity configuration for each network element according to the actual application by virtualizing the network element functions and sharing standardized hardware resources among multiple network elements, which improves the efficiency of network expansion and reduction. Business online efficiency There is a security vulnerability in eCNS280

Trust: 1.53

sources: NVD: CVE-2021-22338 // CNVD: CNVD-2021-55171 // VULMON: CVE-2021-22338

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-55171

AFFECTED PRODUCTS

vendor:huaweimodel:ecns280scope:eqversion:v100r005c10

Trust: 1.0

vendor:huaweimodel:ecns280scope:eqversion:v100r005c00

Trust: 1.0

vendor:huaweimodel:ecns280 v100r005c00scope: - version: -

Trust: 0.6

vendor:huaweimodel:ecns280 v100r005c10scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-55171 // NVD: CVE-2021-22338

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22338
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2021-55171
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202106-1950
value: MEDIUM

Trust: 0.6

VULMON: CVE-2021-22338
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22338
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

CNVD: CNVD-2021-55171
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-22338
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2021-55171 // VULMON: CVE-2021-22338 // CNNVD: CNNVD-202106-1950 // NVD: CVE-2021-22338

PROBLEMTYPE DATA

problemtype:CWE-611

Trust: 1.0

sources: NVD: CVE-2021-22338

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202106-1950

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202106-1950

PATCH

title:Patch for eCNS280 code issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/282096

Trust: 0.6

title:eCNS280 Fixes for code issue vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=155927

Trust: 0.6

sources: CNVD: CNVD-2021-55171 // CNNVD: CNNVD-202106-1950

EXTERNAL IDS

db:NVDid:CVE-2021-22338

Trust: 2.3

db:CNVDid:CNVD-2021-55171

Trust: 0.6

db:CNNVDid:CNNVD-202106-1950

Trust: 0.6

db:VULMONid:CVE-2021-22338

Trust: 0.1

sources: CNVD: CNVD-2021-55171 // VULMON: CVE-2021-22338 // CNNVD: CNNVD-202106-1950 // NVD: CVE-2021-22338

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210421-01-cgp-en

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-22338

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/611.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2021-55171 // VULMON: CVE-2021-22338 // CNNVD: CNNVD-202106-1950 // NVD: CVE-2021-22338

SOURCES

db:CNVDid:CNVD-2021-55171
db:VULMONid:CVE-2021-22338
db:CNNVDid:CNNVD-202106-1950
db:NVDid:CVE-2021-22338

LAST UPDATE DATE

2024-08-14T15:17:11.338000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-55171date:2021-07-27T00:00:00
db:VULMONid:CVE-2021-22338date:2021-07-02T00:00:00
db:CNNVDid:CNNVD-202106-1950date:2021-07-05T00:00:00
db:NVDid:CVE-2021-22338date:2021-07-02T19:58:46.307

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-55171date:2021-07-27T00:00:00
db:VULMONid:CVE-2021-22338date:2021-06-29T00:00:00
db:CNNVDid:CNNVD-202106-1950date:2021-06-29T00:00:00
db:NVDid:CVE-2021-22338date:2021-06-29T19:15:09.147