Vulnerability Description
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions V500R001C00,V500R001C20,V500R001C30;NIP6600 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6300 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6500 versions V500R001C00,V500R001C20,V500R001C30;Secospace USG6600 versions V500R001C00,V500R001C20,V500R001C30,V500R001C50,V500R001C60,V500R001C80;USG9500 versions V500R005C00,V500R005C10.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Nip6300 Firmware | v500r001c00 |
| Huawei | Nip6300 | - |
| Huawei | Nip6600 Firmware | v500r001c00 |
| Huawei | Nip6600 | - |
| Huawei | Secospace Usg6300 Firmware | v500r001c00 |
| Huawei | Secospace Usg6300 | - |
| Huawei | Secospace Usg6500 Firmware | v500r001c00 |
| Huawei | Secospace Usg6500 | - |
| Huawei | Secospace Usg6600 Firmware | v500r001c00 |
| Huawei | Secospace Usg6600 | - |
| Huawei | Usg9500 Firmware | v500r005c00 |
| Huawei | Usg9500 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-plaintVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-plaintVendor Advisory
FAQ
What is CVE-2021-22310?
CVE-2021-22310 is a vulnerability with a CVSS score of 4.4 (MEDIUM). There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in ...
How severe is CVE-2021-22310?
CVE-2021-22310 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22310?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Nip6300 Firmware, Huawei Nip6300, Huawei Nip6600 Firmware, Huawei Nip6600, Huawei Secospace Usg6300 Firmware.