PT-2021-14985 · Huawei · Huawei Ips Module+6
Published
2021-05-12
·
Updated
2021-11-29
·
CVE-2021-22356
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Huawei IPS Module versions V500R005C00SPC100 through V500R005C00SPC200
Huawei NGFW Module versions V500R005C00SPC100 through V500R005C00SPC200
Huawei Secospace USG6300 versions V500R001C30SPC200 through V500R005C00SPC200
Huawei Secospace USG6500 versions V500R001C30SPC200 through V500R005C00SPC200
Huawei Secospace USG6600 versions V500R001C30SPC200 through V500R005C00SPC200
Huawei USG9500 versions V500R001C30SPC200 through V500R005C00SPC200
Description:
A weak secure algorithm is used in a module of Huawei products, allowing attackers to capture and analyze messages between devices to obtain information, potentially leading to an information leak.
Recommendations:
For Huawei IPS Module versions V500R005C00SPC100 through V500R005C00SPC200, update to a version that uses a secure algorithm.
For Huawei NGFW Module versions V500R005C00SPC100 through V500R005C00SPC200, update to a version that uses a secure algorithm.
For Huawei Secospace USG6300 versions V500R001C30SPC200 through V500R005C00SPC200, update to a version that uses a secure algorithm.
For Huawei Secospace USG6500 versions V500R001C30SPC200 through V500R005C00SPC200, update to a version that uses a secure algorithm.
For Huawei Secospace USG6600 versions V500R001C30SPC200 through V500R005C00SPC200, update to a version that uses a secure algorithm.
For Huawei USG9500 versions V500R001C30SPC200 through V500R005C00SPC200, update to a version that uses a secure algorithm.
As a temporary workaround, consider disabling the module that uses the weak secure algorithm until a patch is available.
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ips Module
Huawei Ngfw Module
Huawei Secospace Usg6300
Huawei Secospace Usg6500
Huawei Secospace Usg6600
Huawei Usg9500
Huawei Vrp