SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22363

There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650.

HIGH 7.5EPSS 0.68%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal on affected devices.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.68% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
huawei/ecns280 td firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.