9
CVE-2021-37127
- EPSS 0.1%
- Published 27.10.2021 01:15:07
- Last modified 21.11.2024 06:14:41
- Source psirt@huawei.com
- Teams watchlist Login
- Open Login
There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.
Data is provided by the National Vulnerability Database (NVD)
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00cp2001
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00cp2002
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc100
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc110
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc120
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc200
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc210
Huawei ≫ Imanager Neteco 6000 Firmware Versionv600r010c00spc300
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc100
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc110
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc120
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc190
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc200
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc201
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc202
Huawei ≫ Imanager Neteco Firmware Versionv600r009c00spc210
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.1% | 0.249 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.