Security Advisory

CVE-2021-22338

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-06-29 18:51:23
Last updated 2024-08-03 18:37:18
Assigner huawei
State PUBLISHED

Description

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.