ZeroHour

CVE-2021-22377

CVSS 3.1
7.2 high
EPSS
<1%p58
Published
()
Modified
Description

There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

Vendors
huawei
Products
s12700 firmware, s2700 firmware, s5700 firmware, s6700 firmware, s7700 firmware
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.