ID

VAR-202105-0488


CVE

CVE-2021-22339


TITLE

ManageOne  Vulnerability for inadequate validation of data reliability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-007121

DESCRIPTION

There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal. ManageOne Exists in an inadequate validation of data reliability vulnerabilities.Denial of service (DoS) It may be put into a state. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. Huawei Manageone is a set of cloud data center management solutions of China Huawei (Huawei). The product supports unified management of heterogeneous cloud resource pools, and provides functions such as multi-level VDC matching customer organization model, service catalog planning, self-service, centralized alarm analysis, and intelligent operation and maintenance. There is a security vulnerability in Huawei Manageone. Attackers can use this vulnerability to maliciously construct such parameters, and successfully exploit them to cause certain business exceptions

Trust: 2.34

sources: NVD: CVE-2021-22339 // JVNDB: JVNDB-2021-007121 // CNNVD: CNNVD-202104-975 // VULHUB: VHN-380774 // VULMON: CVE-2021-22339

AFFECTED PRODUCTS

vendor:huaweimodel:manageonescope:eqversion:6.5

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion:8.0.1

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion:6.5.1

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion:8.0.0

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion:6.5.1.1

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion:6.5.0

Trust: 1.0

vendor:huaweimodel:manageonescope:eqversion: -

Trust: 0.8

vendor:huaweimodel:manageonescope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-007121 // NVD: CVE-2021-22339

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22339
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-22339
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202104-975
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202104-2107
value: MEDIUM

Trust: 0.6

VULHUB: VHN-380774
value: LOW

Trust: 0.1

VULMON: CVE-2021-22339
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2021-22339
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-380774
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-22339
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22339
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-380774 // VULMON: CVE-2021-22339 // JVNDB: JVNDB-2021-007121 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202104-2107 // NVD: CVE-2021-22339

PROBLEMTYPE DATA

problemtype:CWE-345

Trust: 1.1

problemtype:Inadequate verification of data reliability (CWE-345) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-380774 // JVNDB: JVNDB-2021-007121 // NVD: CVE-2021-22339

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202104-2107

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

PATCH

title:huawei-sa-20210428-01-dosurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-dos-en

Trust: 0.8

title:Huawei Manageone Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=151402

Trust: 0.6

sources: JVNDB: JVNDB-2021-007121 // CNNVD: CNNVD-202104-2107

EXTERNAL IDS

db:NVDid:CVE-2021-22339

Trust: 3.4

db:JVNDBid:JVNDB-2021-007121

Trust: 0.8

db:CNNVDid:CNNVD-202104-2107

Trust: 0.7

db:CS-HELPid:SB2021041363

Trust: 0.6

db:CNNVDid:CNNVD-202104-975

Trust: 0.6

db:CS-HELPid:SB2021042901

Trust: 0.6

db:VULHUBid:VHN-380774

Trust: 0.1

db:VULMONid:CVE-2021-22339

Trust: 0.1

sources: VULHUB: VHN-380774 // VULMON: CVE-2021-22339 // JVNDB: JVNDB-2021-007121 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202104-2107 // NVD: CVE-2021-22339

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-dos-en

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-22339

Trust: 0.8

url:https://www.cybersecurity-help.cz/vdb/sb2021041363

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021042901

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210428-01-dos-cn

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/345.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-380774 // VULMON: CVE-2021-22339 // JVNDB: JVNDB-2021-007121 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202104-2107 // NVD: CVE-2021-22339

SOURCES

db:VULHUBid:VHN-380774
db:VULMONid:CVE-2021-22339
db:JVNDBid:JVNDB-2021-007121
db:CNNVDid:CNNVD-202104-975
db:CNNVDid:CNNVD-202104-2107
db:NVDid:CVE-2021-22339

LAST UPDATE DATE

2024-08-14T12:05:14.128000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-380774date:2021-05-26T00:00:00
db:VULMONid:CVE-2021-22339date:2021-05-26T00:00:00
db:JVNDBid:JVNDB-2021-007121date:2022-02-03T05:20:00
db:CNNVDid:CNNVD-202104-975date:2021-04-14T00:00:00
db:CNNVDid:CNNVD-202104-2107date:2021-05-27T00:00:00
db:NVDid:CVE-2021-22339date:2021-05-26T14:45:28.653

SOURCES RELEASE DATE

db:VULHUBid:VHN-380774date:2021-05-20T00:00:00
db:VULMONid:CVE-2021-22339date:2021-05-20T00:00:00
db:JVNDBid:JVNDB-2021-007121date:2022-02-03T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-13T00:00:00
db:CNNVDid:CNNVD-202104-2107date:2021-04-28T00:00:00
db:NVDid:CVE-2021-22339date:2021-05-20T20:15:07.323