MEDIUM · 5.3

CVE-2021-22321

There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operat...

Vulnerability Description

There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2700, S5700, S6700 , S7700, S9700, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
HuaweiNip6300 Firmwarev500r001c30
HuaweiNip6300-
HuaweiNip6600 Firmwarev500r001c30
HuaweiNip6600-
HuaweiNip6800 Firmwarev500r001c60
HuaweiNip6800-
HuaweiS12700 Firmwarev200r007c01
HuaweiS12700-
HuaweiS1700 Firmwarev200r009c00spc200
HuaweiS1700-
HuaweiS2700 Firmwarev200r008c00
HuaweiS2700-
HuaweiS5700 Firmwarev200r008c00
HuaweiS5700-
HuaweiS6700 Firmwarev200r008c00
HuaweiS6700-
HuaweiS7700 Firmwarev200r008c00
HuaweiS7700-
HuaweiS9700 Firmwarev200r007c01
HuaweiS9700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22321?

CVE-2021-22321 is a vulnerability with a CVSS score of 5.3 (MEDIUM). There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operat...

How severe is CVE-2021-22321?

CVE-2021-22321 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22321?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Nip6300 Firmware, Huawei Nip6300, Huawei Nip6600 Firmware, Huawei Nip6600, Huawei Nip6800 Firmware.