CVE-2021-37036
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
23/11/2021
Last modified:
28/06/2022
Description
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause the information leak.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:ecns280_td_firmware:v100r005c00:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ecns280_td_firmware:v100r005c10:*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:ecns280_td:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:huawei:fusioncompute:6.5.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page