CVE-2021-22338

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:ecns280_firmware:v100r005c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ecns280_firmware:v100r005c10:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ecns280:-:*:*:*:*:*:*:*

Information

Published : 2021-06-29 12:15

Updated : 2021-07-02 12:58


NVD link : CVE-2021-22338

Mitre link : CVE-2021-22338


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

huawei

  • ecns280_firmware
  • ecns280