7.5

CVE-2021-22332

There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a function is called, the same memory pointer is copied to two functional modules. Attackers can exploit this vulnerability by performing a malicious operation to cause the pointer double free. This may lead to module crash, compromising normal service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HuaweiCloudengine 12800 Firmware Versionv200r002c50spc800
   HuaweiCloudengine 12800 Version-
HuaweiCloudengine 12800 Firmware Versionv200r003c00spc810
   HuaweiCloudengine 12800 Version-
HuaweiCloudengine 12800 Firmware Versionv200r005c00spc800
   HuaweiCloudengine 12800 Version-
HuaweiCloudengine 12800 Firmware Versionv200r005c10spc800
   HuaweiCloudengine 12800 Version-
HuaweiCloudengine 5800 Firmware Versionv200r002c50spc800
   HuaweiCloudengine 5800 Version-
HuaweiCloudengine 5800 Firmware Versionv200r003c00spc810
   HuaweiCloudengine 5800 Version-
HuaweiCloudengine 5800 Firmware Versionv200r005c00spc800
   HuaweiCloudengine 5800 Version-
HuaweiCloudengine 5800 Firmware Versionv200r005c10spc800
   HuaweiCloudengine 5800 Version-
HuaweiCloudengine 6800 Firmware Versionv200r002c50spc800
   HuaweiCloudengine 6800 Version-
HuaweiCloudengine 6800 Firmware Versionv200r003c00spc810
   HuaweiCloudengine 6800 Version-
HuaweiCloudengine 6800 Firmware Versionv200r005c00spc800
   HuaweiCloudengine 6800 Version-
HuaweiCloudengine 6800 Firmware Versionv200r005c10spc800
   HuaweiCloudengine 6800 Version-
HuaweiCloudengine 7800 Firmware Versionv200r002c50spc800
   HuaweiCloudengine 7800 Version-
HuaweiCloudengine 7800 Firmware Versionv200r003c00spc810
   HuaweiCloudengine 7800 Version-
HuaweiCloudengine 7800 Firmware Versionv200r005c00spc800
   HuaweiCloudengine 7800 Version-
HuaweiCloudengine 7800 Firmware Versionv200r005c10spc800
   HuaweiCloudengine 7800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-415 Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.