6.5
CVE-2021-22327
- EPSS 0.16%
- Veröffentlicht 28.04.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:55
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions 10.0.0.186(C10E7R5P1), 10.0.0.186(C461E4R3P1), 10.0.0.188(C00E85R2P11), 10.0.0.188(C01E88R2P11),10.0.0.188(C605E19R1P3), 10.0.0.190(C185E4R7P1), 10.0.0.190(C431E22R2P5), 10.0.0.190(C432E22R2P5),10.0.0.190(C605E19R1P3), 10.0.0.190(C636E4R3P4), 10.0.0.192(C635E3R2P4).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P30 Firmware Version10.0.0.186(c10e7r5p1)
Huawei ≫ P30 Firmware Version10.0.0.186(c461e4r3p1)
Huawei ≫ P30 Firmware Version10.0.0.188(c00e85r2p11)
Huawei ≫ P30 Firmware Version10.0.0.188(c01e88r2p11)
Huawei ≫ P30 Firmware Version10.0.0.188(c605e19r1p3)
Huawei ≫ P30 Firmware Version10.0.0.190(c185e4r7p1)
Huawei ≫ P30 Firmware Version10.0.0.190(c431e22r2p5)
Huawei ≫ P30 Firmware Version10.0.0.190(c432e22r2p5)
Huawei ≫ P30 Firmware Version10.0.0.190(c605e19r1p3)
Huawei ≫ P30 Firmware Version10.0.0.190(c636e4r3p4)
Huawei ≫ P30 Firmware Version10.0.0.192(c635e3r2p4)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.337 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.