{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T09:07:45.338","vulnerabilities":[{"cve":{"id":"CVE-2021-22309","sourceIdentifier":"psirt@huawei.com","published":"2021-03-22T18:15:14.433","lastModified":"2024-11-21T05:49:53.087","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00."},{"lang":"es","value":"Se presenta una vulnerabilidad de algoritmo no seguro en unos productos Huawei.&#xa0;Un módulo usa una entrada poco aleatoria en un mecanismo seguro.&#xa0;Unos atacantes pueden explotar esta vulnerabilidad mediante fuerza bruta para obtener mensajes confidenciales.&#xa0;Esto puede conllevar a un filtrado de información.&#xa0;Las versiones de producto afectadas incluyen: USG9500 versiones V500R001C30SPC200, V500R001C60SPC500, V500R005C00SPC200; USG9520 versiones V500R005C00; USG9560 versiones V500R005C00; USG9580 versiones V500R005C00"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-330"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9500_firmware:v500r001c30spc200:*:*:*:*:*:*:*","matchCriteriaId":"C0BF5257-8CD1-4951-9C53-07B85D468F8B"},{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9500_firmware:v500r001c60spc500:*:*:*:*:*:*:*","matchCriteriaId":"8A1EFB9D-5349-4EAF-9880-34F0D20011E4"},{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9500_firmware:v500r005c00spc200:*:*:*:*:*:*:*","matchCriteriaId":"ADA71C5D-4B11-401D-AEC9-907204C21476"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:usg9500:-:*:*:*:*:*:*:*","matchCriteriaId":"4B6064BB-5E62-4D70-B933-05B5426EEE9C"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9520_firmware:v500r005c00:*:*:*:*:*:*:*","matchCriteriaId":"6CAE4B21-DB0F-46BA-AEEF-878CFE2CB120"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:usg9520:-:*:*:*:*:*:*:*","matchCriteriaId":"60030EDB-682F-4107-80FC-5F03CE75131D"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9560_firmware:v500r005c00:*:*:*:*:*:*:*","matchCriteriaId":"752FD81F-0750-4200-B732-304306D31BF9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:usg9560:-:*:*:*:*:*:*:*","matchCriteriaId":"96AFE94D-EDC7-4372-A1BF-8089D5551AD9"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:usg9580_firmware:v500r005c00:*:*:*:*:*:*:*","matchCriteriaId":"F890E352-DB01-4BF0-A709-0F63AE3F91AE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:usg9580:-:*:*:*:*:*:*:*","matchCriteriaId":"14C9D3E2-B016-4238-A170-6C4AD1B3B76C"}]}]}],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210202-01-fw-en","source":"psirt@huawei.com","tags":["Vendor Advisory"]},{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210202-01-fw-en","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}