Security readout for executives and security teams
Plain-English summary
This CVE affects specific Huawei eCNS280 and eSE620X vESS versions. A low-privileged attacker may be able to access files without proper authorization and escalate privileges in a specific scenario, potentially disrupting normal service. Public severity, CVSS, and fix details were not provided in the source bundle.
Executive priority
Prioritize this if the organization operates the affected Huawei carrier or service platforms. With no public CVSS or exploitation evidence in the bundle, urgency should be driven by asset criticality, vendor guidance, and whether low-privileged users can access the affected systems.
Technical view
CVE-2021-22361 is an improper authorization issue involving incorrectly authorized file access. The listed affected versions are eCNS280 V100R005C00 and V100R005C10, plus eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. The source describes possible privilege escalation by a low-access attacker under specific conditions.
Likely exposure
Exposure appears limited to organizations running the named Huawei eCNS280 or eSE620X vESS versions. The bundle provides no CPEs, deployment details, internet exposure indicators, or affected configuration prerequisites, so inventory validation is the primary first step.
Exploitation context
The source bundle does not cite active exploitation, proof-of-concept availability, or KEV listing. It only states that a low-access attacker may exploit the issue in a specific scenario. Treat exploitation status as unconfirmed.
Researcher notes
Evidence is sparse: no CVSS vector, CWE mapping, patch detail, or exploitation confirmation is included. The key research task is to map product/version exposure and obtain Huawei advisory details before making remediation or detection claims beyond improper authorization and potential privilege escalation.
Mitigation direction
- Check Huawei PSIRT guidance for fixed versions or vendor-recommended mitigations.
- Identify and prioritize affected eCNS280 and eSE620X vESS deployments.
- Restrict low-privileged access to affected systems until vendor guidance is applied.
- Monitor affected platforms for unusual file access or privilege changes.
Validation and detection
- Confirm whether affected Huawei products and exact versions exist in inventory.
- Review local access controls for low-privileged users on affected systems.
- Check vendor advisory status for patches, workarounds, or upgrade paths.
- Verify logs for privilege escalation indicators or unauthorized file access.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Privilege behavior lookup
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2021-22361 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210519-02-cgp-enCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
