VYPR

Ecns280 Firmware

by Huawei

CVEs (3)

  • CVE-2021-22361HigJun 22, 2021
    risk 0.51cvss 7.8epss 0.00

    There is an improper authorization vulnerability in eCNS280 V100R005C00, V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200. A file access is not authorized correctly. Attacker with low access may launch privilege escalation in a specific scenario. This may…

  • CVE-2021-22292HigFeb 6, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.

  • CVE-2021-22338MedJun 29, 2021
    risk 0.35cvss 5.3epss 0.01

    There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.