CVE-2021-22362

MEDIUM

Huawei CloudEngine 12800, 5800, 6800, 7800 Firmware - Out-of-bounds Write via Crafted Packet Data

Title source: llm
STIX 2.1

Description

There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sending crafted data in the packet to the target device. Due to insufficient validation of message, successful exploit can cause certain service abnormal.Affected product versions include:CloudEngine 12800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800;CloudEngine 5800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800@;CloudEngine 6800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800,V200R019C10SPC800;CloudEngine 7800 versions V200R002C50SPC800,V200R003C00SPC810,V200R005C00SPC800,V200R005C10SPC800,V200R019C00SPC800,V200R019C10SPC800.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0018
EPSS Percentile 38.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-787
Status published
Products (25)
huawei/cloudengine_12800_firmware v200r002c50spc800
huawei/cloudengine_12800_firmware v200r003c00spc810
huawei/cloudengine_12800_firmware v200r005c00spc800
huawei/cloudengine_12800_firmware v200r005c10spc800
huawei/cloudengine_12800_firmware v200r019c00spc800
huawei/cloudengine_12800_firmware v200r019c10spc800
huawei/cloudengine_5800_firmware v200r002c50spc800
huawei/cloudengine_5800_firmware v200r003c00spc810
huawei/cloudengine_5800_firmware v200r005c00spc800
huawei/cloudengine_5800_firmware v200r005c10spc800
... and 15 more
Published May 27, 2021
Tracked Since Feb 18, 2026