PT-2021-15006 · Huawei · S2700+5

Published

2021-06-02

·

Updated

2021-06-29

·

CVE-2021-22377

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: S12700 version V200R019C00SPC500 S2700 version V200R019C00SPC500 S5700 version V200R019C00SPC500 S6700 version V200R019C00SPC500 S7700 version V200R019C00SPC500
Description: There is a command injection issue in certain Huawei products. A module does not verify specific input sufficiently, allowing attackers to exploit this by sending malicious parameters to inject commands. This can compromise normal service.
Recommendations: For S12700 version V200R019C00SPC500, update to a version that includes the fix for this issue. For S2700 version V200R019C00SPC500, update to a version that includes the fix for this issue. For S5700 version V200R019C00SPC500, update to a version that includes the fix for this issue. For S6700 version V200R019C00SPC500, update to a version that includes the fix for this issue. For S7700 version V200R019C00SPC500, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the module that does not verify specific input sufficiently until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22377

Affected Products

Huawei Vrp
S12700
S2700
S5700
S6700
S7700