MEDIUM · 5.5

CVE-2021-37036

There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can ob...

Vulnerability Description

There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HuaweiEcns280 Td Firmwarev100r005c00
HuaweiEcns280 Td-
HuaweiFusioncompute6.5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-37036?

CVE-2021-37036 is a vulnerability with a CVSS score of 5.5 (MEDIUM). There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can ob...

How severe is CVE-2021-37036?

CVE-2021-37036 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-37036?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ecns280 Td Firmware, Huawei Ecns280 Td, Huawei Fusioncompute.