PT-2021-14931 · Huawei · Ecns280+1
Published
2021-01-13
·
Updated
2022-07-12
·
CVE-2021-22292
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
eCNS280 versions V100R005C00, V100R005C10
Description:
The issue is a denial of service (DoS) vulnerability due to a design defect. Remote unauthorized attackers can send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.
Recommendations:
For eCNS280 versions V100R005C00 and V100R005C10, consider implementing rate limiting on incoming messages to prevent system resource exhaustion until a patch is available.
As a temporary workaround, restrict access to the affected devices to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei Vrp
Ecns280