Got it

CVE-2021-3449 CVE-2021-3450

Created: Apr 1, 2021 19:17:22Latest reply: Apr 5, 2021 09:09:25 607 5 1 0 0
  HiCoins as reward: 0 (problem unresolved)

Hi,

Where can I find if switches S7700, S5710, S9300, CE6563 are vulnerable to CVE-2021-3449 or CVE-2021-3449 - related to OpenSSL 1.1.1-1.1.1j (released on 25.03.2021) ?

I tried Security Advisory in Product Support but there is no reference to the case


Regards, Piotr Laniec

Featured Answers

Recommended answer

Popeye_Wang
Admin Created Apr 5, 2021 09:09:25

Hi,
Huawei has announced this vulnerability, and related devices should be patched.
Please refer to:
https://www.huawei.com/ca/psirt/security-notices/huawei-sn-20210210-01-sudo-en
But the device you mentioned should not be involved in this vulnerability.
View more
  • x
  • convention:

PiotrekRGC
PiotrekRGC Created Apr 6, 2021 07:39:35 (0) (0)
Hi,
Sorry but the announcement you mentioned refers to another CVE.
I am in an official contact with Huawei now.  
Popeye_Wang
Popeye_Wang Reply PiotrekRGC  Created Apr 6, 2021 10:00:24 (0) (0)
Sorry I misread it. These are two new vulnerabilities and the bulletin should not have been updated. I guess that using ssl authentication on older devices might be affected by CVE-201-3449(DoS attack).
Anyway, hope you will get an official response soon.  
All Answers
Hi,
I don't think the devices will be vulnerable to CVE-2021-3449. As far as I know, CVE-2021-3449 affects the OpenSSL TLS server while the devices you listed don't support working as a TLS server.
Anyway, that's my viewpoint, and it's better that Huawei provides an official annoucement.
View more
  • x
  • convention:

PiotrekRGC
PiotrekRGC Created Apr 3, 2021 07:41:17 (0) (0)
Hi,
Thanks for your reply.
You may be right but switches like s77, S93, ce68 use openssl (check Open Source Software Notice documents for the models) and in V200r019 (v200r009 for CE) it is v1.1.1 of openssl so there might be the case. I do not know the conditions of use (ssl is part of the "internal" software) and there may not be any threat. Nevertheless some other vendors have released statements on the case that's why I think I just have to wait.  
Hi,
Huawei has announced this vulnerability, and related devices should be patched.
Please refer to:
https://www.huawei.com/ca/psirt/security-notices/huawei-sn-20210210-01-sudo-en
But the device you mentioned should not be involved in this vulnerability.
View more
  • x
  • convention:

PiotrekRGC
PiotrekRGC Created Apr 6, 2021 07:39:35 (0) (0)
Hi,
Sorry but the announcement you mentioned refers to another CVE.
I am in an official contact with Huawei now.  
Popeye_Wang
Popeye_Wang Reply PiotrekRGC  Created Apr 6, 2021 10:00:24 (0) (0)
Sorry I misread it. These are two new vulnerabilities and the bulletin should not have been updated. I guess that using ssl authentication on older devices might be affected by CVE-201-3449(DoS attack).
Anyway, hope you will get an official response soon.  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.