ID

VAR-202102-0647


CVE

CVE-2021-22307


TITLE

Mate 30  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-010464

DESCRIPTION

There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the modules that should be protected. Local attackers can exploit this vulnerability to affect the integrity of certain module. Mate 30 Exists in unspecified vulnerabilities.Information may be tampered with. Huawei Mate 30 is a smart phone of China's Huawei (Huawei) company

Trust: 2.25

sources: NVD: CVE-2021-22307 // JVNDB: JVNDB-2021-010464 // CNVD: CNVD-2021-07517 // VULMON: CVE-2021-22307

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-07517

AFFECTED PRODUCTS

vendor:huaweimodel:mate 30scope:eqversion:10.0.0.203\(c00e201r7p2\)

Trust: 1.0

vendor:huaweimodel:mate 30scope:eqversion: -

Trust: 0.8

vendor:huaweimodel:mate 30scope:eqversion:mate 30 firmware 10.0.0.203(c00e201r7p2)

Trust: 0.8

vendor:huaweimodel:mate 10.0.0.203scope:eqversion:30

Trust: 0.6

sources: CNVD: CNVD-2021-07517 // JVNDB: JVNDB-2021-010464 // NVD: CVE-2021-22307

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22307
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-22307
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2021-07517
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202102-517
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2021-22307
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-07517
severity: MEDIUM
baseScore: 4.7
vectorString: AV:L/AC:H/AU:N/C:N/I:C/A:P
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 1.9
impactScore: 7.8
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-22307
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-22307
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-07517 // JVNDB: JVNDB-2021-010464 // CNNVD: CNNVD-202102-517 // NVD: CVE-2021-22307

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-010464 // NVD: CVE-2021-22307

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202102-517

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202102-517

PATCH

title:huawei-sa-20210127-06-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-06-smartphone-en

Trust: 0.8

title:Patch for Huawei Mate 30 weak algorithm vulnerability (CVE-2021-22307)url:https://www.cnvd.org.cn/patchInfo/show/245996

Trust: 0.6

title:Huawei Mate 30 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=140800

Trust: 0.6

sources: CNVD: CNVD-2021-07517 // JVNDB: JVNDB-2021-010464 // CNNVD: CNNVD-202102-517

EXTERNAL IDS

db:NVDid:CVE-2021-22307

Trust: 3.9

db:JVNDBid:JVNDB-2021-010464

Trust: 0.8

db:CNVDid:CNVD-2021-07517

Trust: 0.6

db:CNNVDid:CNNVD-202102-517

Trust: 0.6

db:VULMONid:CVE-2021-22307

Trust: 0.1

sources: CNVD: CNVD-2021-07517 // VULMON: CVE-2021-22307 // JVNDB: JVNDB-2021-010464 // CNNVD: CNNVD-202102-517 // NVD: CVE-2021-22307

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-06-smartphone-en

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-22307

Trust: 1.4

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2021-07517 // VULMON: CVE-2021-22307 // JVNDB: JVNDB-2021-010464 // CNNVD: CNNVD-202102-517 // NVD: CVE-2021-22307

SOURCES

db:CNVDid:CNVD-2021-07517
db:VULMONid:CVE-2021-22307
db:JVNDBid:JVNDB-2021-010464
db:CNNVDid:CNNVD-202102-517
db:NVDid:CVE-2021-22307

LAST UPDATE DATE

2024-11-23T21:58:48.556000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-07517date:2021-01-31T00:00:00
db:VULMONid:CVE-2021-22307date:2021-02-10T00:00:00
db:JVNDBid:JVNDB-2021-010464date:2022-07-01T08:15:00
db:CNNVDid:CNNVD-202102-517date:2021-02-18T00:00:00
db:NVDid:CVE-2021-22307date:2024-11-21T05:49:52.870

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-07517date:2021-01-31T00:00:00
db:VULMONid:CVE-2021-22307date:2021-02-06T00:00:00
db:JVNDBid:JVNDB-2021-010464date:2022-07-01T00:00:00
db:CNNVDid:CNNVD-202102-517date:2021-02-05T00:00:00
db:NVDid:CVE-2021-22307date:2021-02-06T00:15:13.327