PiotrekRGC
Created Apr 6, 2021 07:39:35
(0)
(0)
Hi, Sorry but the announcement you mentioned refers to another CVE. I am in an official contact with Huawei now.
Popeye_Wang
Reply PiotrekRGC Created Apr 6, 2021 10:00:24
(0)
(0)
Sorry I misread it. These are two new vulnerabilities and the bulletin should not have been updated. I guess that using ssl authentication on older devices might be affected by CVE-201-3449(DoS attack). Anyway, hope you will get an official response soon. |
PiotrekRGC
Created Apr 3, 2021 07:41:17
(0)
(0)
Hi, Thanks for your reply. You may be right but switches like s77, S93, ce68 use openssl (check Open Source Software Notice documents for the models) and in V200r019 (v200r009 for CE) it is v1.1.1 of openssl so there might be the case. I do not know the conditions of use (ssl is part of the "internal" software) and there may not be any threat. Nevertheless some other vendors have released statements on the case that's why I think I just have to wait. |
PiotrekRGC
Created Apr 6, 2021 07:39:35
(0)
(0)
Hi, Sorry but the announcement you mentioned refers to another CVE. I am in an official contact with Huawei now.
Popeye_Wang
Reply PiotrekRGC Created Apr 6, 2021 10:00:24
(0)
(0)
Sorry I misread it. These are two new vulnerabilities and the bulletin should not have been updated. I guess that using ssl authentication on older devices might be affected by CVE-201-3449(DoS attack). Anyway, hope you will get an official response soon. |