
CVE-2021-40007
https://notcve.org/view.php?id=CVE-2021-40007
13 Dec 2021 — There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure. Se presenta una vulnerabilidad de filtrado de información en eCNS280_TD V100R005C10SPC650. La vulnerabilidad está causada por una administración inapropiada de la salida del registro. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211208-01-informationleak-en • CWE-116: Improper Encoding or Escaping of Output •

CVE-2021-39995
https://notcve.org/view.php?id=CVE-2021-39995
29 Nov 2021 — Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. Algunos productos de Huawei usan el software OpenHpi para la administración del hardware. Una función que analiza los datos devueltos por OpenHpi contiene una vulnerabilidad de le... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211124-03-dos-en • CWE-125: Out-of-bounds Read •

CVE-2021-37036
https://notcve.org/view.php?id=CVE-2021-37036
23 Nov 2021 — There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak. Se presenta una vulnerabilidad de filtrado de información en FusionCompute versiones 6.5.1, eCNS280_TD V100R005C00 y V100R005C10. Debido al almacenamiento inapropiado de información específica en el archiv... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210818-01-informationleak-en • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2021-22396
https://notcve.org/view.php?id=CVE-2021-22396
02 Aug 2021 — There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200. Se presenta una vulnerabilidad de escalada de privilegios en algunos productos de Huawei. Debido a una inapropiada administración de priv... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210714-01-privilege-en • CWE-269: Improper Privilege Management •

CVE-2021-22383
https://notcve.org/view.php?id=CVE-2021-22383
22 Jun 2021 — There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit this vulnerability by sending a specific message to the target device, which could cause a Denial of Service (DoS). Se presenta una vulnerabilidad de lectura fuera de límites en eCNS280_TD V100R005C10 y eSE620X vESS V100R001C10SPC200, V... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210616-01-cgp-en • CWE-125: Out-of-bounds Read •

CVE-2021-22363
https://notcve.org/view.php?id=CVE-2021-22363
22 Jun 2021 — There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices. Se presenta una vulnerabilidad de error de administración de recursos en eCNS280_TD V100R005C10SPC650. Un atacante necesita llevar a cabo operaciones específicas para explotar la vulnerabilid... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210609-01-resource-en • CWE-770: Allocation of Resources Without Limits or Throttling •

CVE-2021-22378
https://notcve.org/view.php?id=CVE-2021-22378
22 Jun 2021 — There is a race condition vulnerability in eCNS280_TD V100R005C00 and V100R005C10. There is a timing window exists in which the database can be operated by another thread that is operating concurrently. Successful exploit may cause the affected device abnormal. Se presenta una vulnerabilidad de condición de carrera en eCNS280_TD V100R005C00 y V100R005C10. Se presenta una ventana de servicios en la que la base de datos puede ser operada por otro hilo que esté operando concurrentemente. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210602-01-cgp-en • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2021-22300
https://notcve.org/view.php?id=CVE-2021-22300
06 Feb 2021 — There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods. Se presenta una vulnerabilidad de filtrado de información en eCNS280_TD versiones V100R005C00 y V100R005C10. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-01-cgp-en • CWE-312: Cleartext Storage of Sensitive Information •