7.5

CVE-2021-37129

There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC500,V200R019C10SPC200,V200R020C00,V200R020C10;S1700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S2700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S5700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600,V200R019C00SPC500;S6700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S7700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600;S9700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;USG9500 V500R005C00,V500R005C20.

Data is provided by the National Vulnerability Database (NVD)
HuaweiIps Module Firmware Versionv500r005c00
   HuaweiIps Module Version-
HuaweiIps Module Firmware Versionv500r005c20
   HuaweiIps Module Version-
HuaweiNgfw Module Firmware Versionv500r005c00
   HuaweiNgfw Module Version-
HuaweiNip6600 Firmware Versionv500r005c00
   HuaweiNip6600 Version-
HuaweiNip6600 Firmware Versionv500r005c20
   HuaweiNip6600 Version-
HuaweiS12700 Firmware Versionv200r010c00spc600
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r011c10spc500
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r011c10spc600
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r013c00spc500
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r019c00spc200
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r019c00spc500
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r019c10spc200
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r020c00
   HuaweiS12700 Version-
HuaweiS12700 Firmware Versionv200r020c10
   HuaweiS12700 Version-
HuaweiS1700 Firmware Versionv200r010c00spc600
   HuaweiS1700 Version-
HuaweiS1700 Firmware Versionv200r011c10spc500
   HuaweiS1700 Version-
HuaweiS1700 Firmware Versionv200r011c10spc600
   HuaweiS1700 Version-
HuaweiS2700 Firmware Versionv200r010c00spc600
   HuaweiS2700 Version-
HuaweiS2700 Firmware Versionv200r011c10spc500
   HuaweiS2700 Version-
HuaweiS2700 Firmware Versionv200r011c10spc600
   HuaweiS2700 Version-
HuaweiS5700 Firmware Versionv200r010c00spc600
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r010c00spc700
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r011c10spc500
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r011c10spc600
   HuaweiS5700 Version-
HuaweiS5700 Firmware Versionv200r019c00spc500
   HuaweiS5700 Version-
HuaweiS6700 Firmware Versionv200r010c00spc600
   HuaweiS6700 Version-
HuaweiS6700 Firmware Versionv200r011c10spc500
   HuaweiS6700 Version-
HuaweiS6700 Firmware Versionv200r011c10spc600
   HuaweiS6700 Version-
HuaweiS7700 Firmware Versionv200r010c00spc600
   HuaweiS7700 Version-
HuaweiS7700 Firmware Versionv200r010c00spc700
   HuaweiS7700 Version-
HuaweiS7700 Firmware Versionv200r011c10spc500
   HuaweiS7700 Version-
HuaweiS7700 Firmware Versionv200r011c10spc600
   HuaweiS7700 Version-
HuaweiS9700 Firmware Versionv200r010c00spc600
   HuaweiS9700 Version-
HuaweiS9700 Firmware Versionv200r011c10spc500
   HuaweiS9700 Version-
HuaweiS9700 Firmware Versionv200r011c10spc600
   HuaweiS9700 Version-
HuaweiUsg9500 Firmware Versionv500r005c00
   HuaweiUsg9500 Version-
HuaweiUsg9500 Firmware Versionv500r005c20
   HuaweiUsg9500 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.367
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.