QID 43873

Date Published: 2021-10-19

QID 43873: Huawei Switch Command Injection Vulnerability (Huawei-SA-20210602-01)

There is a command injection vulnerability in Huawei products. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service. (Vulnerability ID: HWPSIRT-2020-96403)

A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal service.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20210602-01 for updates and patch information.

    CVEs related to QID 43873

    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20210602-01 URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20210602-01-cmdinj-en