Vulnerability Description
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Usg9500 Firmware | v500r001c30spc200 |
| Huawei | Usg9500 | - |
| Huawei | Usg9520 Firmware | v500r005c00 |
| Huawei | Usg9520 | - |
| Huawei | Usg9560 Firmware | v500r005c00 |
| Huawei | Usg9560 | - |
| Huawei | Usg9580 Firmware | v500r005c00 |
| Huawei | Usg9580 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210202-01-fw-enVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210202-01-fw-enVendor Advisory
FAQ
What is CVE-2021-22309?
CVE-2021-22309 is a vulnerability with a CVSS score of 7.5 (HIGH). There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive messa...
How severe is CVE-2021-22309?
CVE-2021-22309 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22309?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Usg9500 Firmware, Huawei Usg9500, Huawei Usg9520 Firmware, Huawei Usg9520, Huawei Usg9560 Firmware.