ID

VAR-202105-0490


CVE

CVE-2021-22359


TITLE

Huawei S5700  and  S6700  Input confirmation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2021-007380

DESCRIPTION

There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C00SPC500 of S6700. An attacker could exploit this vulnerability by sending specific message to a targeted device. Due to insufficient input validation, successful exploit can cause the service abnormal. Huawei S5700 and S6700 Is vulnerable to input validation.Denial of service (DoS) It may be put into a state. The Huawei S5700 and Huawei S6700 are both enterprise-class switches from the Chinese company Huawei. The vulnerability stems from the program not properly validating the input. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements

Trust: 2.7

sources: NVD: CVE-2021-22359 // JVNDB: JVNDB-2021-007380 // CNVD: CNVD-2022-04713 // CNNVD: CNNVD-202104-975

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-04713

AFFECTED PRODUCTS

vendor:huaweimodel:s5700scope:eqversion:v200r005c00spc500

Trust: 1.0

vendor:huaweimodel:s6700scope:eqversion:v200r005c00spc500

Trust: 1.0

vendor:huaweimodel:s6700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5700scope: - version: -

Trust: 0.8

vendor:huaweimodel:s5700 v200r005c00spc500scope: - version: -

Trust: 0.6

vendor:huaweimodel:s6700 v200r005c00spc500scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2022-04713 // JVNDB: JVNDB-2021-007380 // NVD: CVE-2021-22359

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22359
value: HIGH

Trust: 1.0

NVD: CVE-2021-22359
value: HIGH

Trust: 0.8

CNVD: CNVD-2022-04713
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202104-975
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202105-1292
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2021-22359
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2022-04713
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-22359
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22359
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-04713 // JVNDB: JVNDB-2021-007380 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1292 // NVD: CVE-2021-22359

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.0

problemtype:Incorrect input confirmation (CWE-20) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-007380 // NVD: CVE-2021-22359

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202105-1292

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202104-975

PATCH

title:huawei-sa-20210519-02-dosurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210519-02-dos-en

Trust: 0.8

title:Patch for Huawei S5700 and S5800 Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/314226

Trust: 0.6

title:Huawei router Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=152809

Trust: 0.6

sources: CNVD: CNVD-2022-04713 // JVNDB: JVNDB-2021-007380 // CNNVD: CNNVD-202105-1292

EXTERNAL IDS

db:NVDid:CVE-2021-22359

Trust: 3.8

db:JVNDBid:JVNDB-2021-007380

Trust: 0.8

db:CNVDid:CNVD-2022-04713

Trust: 0.6

db:CS-HELPid:SB2021041363

Trust: 0.6

db:CNNVDid:CNNVD-202104-975

Trust: 0.6

db:CS-HELPid:SB2021052002

Trust: 0.6

db:CNNVDid:CNNVD-202105-1292

Trust: 0.6

sources: CNVD: CNVD-2022-04713 // JVNDB: JVNDB-2021-007380 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1292 // NVD: CVE-2021-22359

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2021-22359

Trust: 2.0

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210519-02-dos-en

Trust: 1.6

url:https://www.cybersecurity-help.cz/vdb/sb2021041363

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021052002

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20210519-02-dos-cn

Trust: 0.6

sources: CNVD: CNVD-2022-04713 // JVNDB: JVNDB-2021-007380 // CNNVD: CNNVD-202104-975 // CNNVD: CNNVD-202105-1292 // NVD: CVE-2021-22359

SOURCES

db:CNVDid:CNVD-2022-04713
db:JVNDBid:JVNDB-2021-007380
db:CNNVDid:CNNVD-202104-975
db:CNNVDid:CNNVD-202105-1292
db:NVDid:CVE-2021-22359

LAST UPDATE DATE

2024-08-14T12:18:20.723000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-04713date:2022-01-18T00:00:00
db:JVNDBid:JVNDB-2021-007380date:2022-02-09T08:14:00
db:CNNVDid:CNNVD-202104-975date:2021-04-14T00:00:00
db:CNNVDid:CNNVD-202105-1292date:2021-06-07T00:00:00
db:NVDid:CVE-2021-22359date:2021-06-04T19:34:24.590

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-04713date:2022-01-18T00:00:00
db:JVNDBid:JVNDB-2021-007380date:2022-02-09T00:00:00
db:CNNVDid:CNNVD-202104-975date:2021-04-13T00:00:00
db:CNNVDid:CNNVD-202105-1292date:2021-05-19T00:00:00
db:NVDid:CVE-2021-22359date:2021-05-27T13:15:07.897