Vulnerability Description
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | S12700 Firmware | v200r019c00spc500 |
| Huawei | S12700 | - |
| Huawei | S2700 Firmware | v200r019c00spc500 |
| Huawei | S2700 | - |
| Huawei | S5700 Firmware | v200r019c00spc500 |
| Huawei | S5700 | - |
| Huawei | S6700 Firmware | v200r019c00spc500 |
| Huawei | S6700 | - |
| Huawei | S7700 Firmware | v200r019c00spc500 |
| Huawei | S7700 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210602-01-cmdinjVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210602-01-cmdinjVendor Advisory
FAQ
What is CVE-2021-22377?
CVE-2021-22377 is a vulnerability with a CVSS score of 7.2 (HIGH). There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify ...
How severe is CVE-2021-22377?
CVE-2021-22377 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22377?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei S12700 Firmware, Huawei S12700, Huawei S2700 Firmware, Huawei S2700, Huawei S5700 Firmware.