There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.
2021-06-29T19:15:09.147
2024-11-21T05:49:56.330
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | ecns280_firmware | v100r005c00 | Yes |
| Operating System | huawei | ecns280_firmware | v100r005c10 | Yes |
| Hardware | huawei | ecns280 | - | No |