9

CVE-2021-37127

There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.

Data is provided by the National Vulnerability Database (NVD)
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00cp2001
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00cp2002
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc100
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc110
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc120
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc200
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc210
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco 6000 Firmware Versionv600r010c00spc300
   HuaweiImanager Neteco 6000 Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc100
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc110
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc120
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc190
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc200
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc201
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc202
   HuaweiImanager Neteco Version-
HuaweiImanager Neteco Firmware Versionv600r009c00spc210
   HuaweiImanager Neteco Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.249
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.