CVE Feed

    Dashboard / CVE / CVE-2021-22309

    CVE-2021-22309

    There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00.

    Published:Mar 22, 2021
    Last Modified:Nov 21, 2024
    EPS:Mar 22, 2021
    EPSS Score:0.00151
    CVSS Score:7.5

    Affected Products

    Vendor
    Huawei
    Product
    Usg9500
    Vendor
    Huawei
    Product
    Usg9500 Firmware
    Vendor
    Huawei
    Product
    Usg9520
    Vendor
    Huawei
    Product
    Usg9520 Firmware
    Vendor
    Huawei
    Product
    Usg9560
    Vendor
    Huawei
    Product
    Usg9560 Firmware
    Vendor
    Huawei
    Product
    Usg9580
    Vendor
    Huawei
    Product
    Usg9580 Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High