HIGH
Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability
Published Feb 6, 2021
7.5
HIGHCVSS 3.1
EPSS 0.91%
Description
Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1RC2, 8.0.RC2. Affected product versions include: Taurus-AL00A versions 10.0.0.1(C00E1R1P1).
Affected products
- Vendor n/a Product CampusInsight Defaultn/a
- Version V100R019C10StatusaffectedConstraints-
- Version
- Vendor n/a Product ManageOne Defaultn/a
- Version 6.5.1.1StatusaffectedConstraints-
- Version 6.5.1.SPC100StatusaffectedConstraints-
- Version 6.5.1.SPC200StatusaffectedConstraints-
- Version 6.5.1RC1StatusaffectedConstraints-
- Version 6.5.1RC2StatusaffectedConstraints-
- Version 8.0.RC2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | CampusInsight | n/a |
| |||||||||||||||||||||
| n/a | ManageOne | n/a |
|
Configuration 1
Configuration 2
AND
- 10.0.0.1\(c00e1r1p1\)
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210120-01-http-en x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210120-01-http-en | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner huawei
Published Feb 6, 2021
Updated Aug 3, 2024
Reserved Jan 5, 2021
Link CVE-2021-22293
CISA Vulnrichment
Updated n/a