There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.
2021-02-06T01:15:13.747
2024-11-21T05:49:52.147
Modified
CVSSv3.1: 4.1 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | ecns280_td_firmware | v100r005c00 | Yes |
| Operating System | huawei | ecns280_td_firmware | v100r005c10 | Yes |
| Hardware | huawei | ecns280_td | - | No |