CVE-2021-22365
Last modified
CVE-2021-22365 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
There is an out of bounds read vulnerability in eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. A local attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of internal message, successful exploit may cause the process and the service abnormal.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ese620x Vess Firmware | v100r001c10spc200 |
| Huawei | Ese620x Vess Firmware | v100r001c20spc200 |
| Huawei | Ese620x Vess Firmware | v200r001c00spc300 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22365?
How severe is CVE-2021-22365?
How do I fix CVE-2021-22365?
Are you affected by CVE-2021-22365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
