PT-2021-14948 · Huawei · Nip6300+6
Published
2021-02-03
·
Updated
2021-03-26
·
CVE-2021-22310
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
NIP6300 versions V500R001C00 through V500R001C30
NIP6600 versions V500R001C00 through V500R001C30
Secospace USG6300 versions V500R001C00 through V500R001C30
Secospace USG6500 versions V500R001C00 through V500R001C30
Secospace USG6600 versions V500R001C00 through V500R001C80
USG9500 versions V500R005C00 through V500R005C10
Description:
There is an information leakage issue in some Huawei products due to improper storage of specific information in the log file. When a user logs in to the device, an attacker can obtain this information, potentially causing an information leak.
Recommendations:
For NIP6300 versions V500R001C00 through V500R001C30, update to a version that fixes the information leakage issue.
For NIP6600 versions V500R001C00 through V500R001C30, update to a version that fixes the information leakage issue.
For Secospace USG6300 versions V500R001C00 through V500R001C30, update to a version that fixes the information leakage issue.
For Secospace USG6500 versions V500R001C00 through V500R001C30, update to a version that fixes the information leakage issue.
For Secospace USG6600 versions V500R001C00 through V500R001C80, update to a version that fixes the information leakage issue.
For USG9500 versions V500R005C00 through V500R005C10, update to a version that fixes the information leakage issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Vrp
Nip6300
Nip6600
Secospace Usg6300
Secospace Usg6500
Secospace Usg6600
Usg9500