CVE-2021-22338

MEDIUM

Huawei eCNS280 V100R005C00 and V100R005C10 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0015
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-611
Status published
Products (2)
huawei/ecns280_firmware v100r005c00
huawei/ecns280_firmware v100r005c10
Published Jun 29, 2021
Tracked Since Feb 18, 2026