ID

VAR-202108-2195


CVE

CVE-2021-22384


TITLE

Huawei  Race condition vulnerabilities in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2021-010878

DESCRIPTION

There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass. Huawei There are race condition vulnerabilities in smartphones.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.8

sources: NVD: CVE-2021-22384 // JVNDB: JVNDB-2021-010878 // VULHUB: VHN-380819 // VULMON: CVE-2021-22384

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:11.0.0

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:4.0.0

Trust: 1.0

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

vendor:huaweimodel:magic uiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-010878 // NVD: CVE-2021-22384

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22384
value: HIGH

Trust: 1.0

NVD: CVE-2021-22384
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202108-102
value: HIGH

Trust: 0.6

VULHUB: VHN-380819
value: MEDIUM

Trust: 0.1

VULMON: CVE-2021-22384
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-22384
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-380819
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-22384
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.2
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-22384
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-380819 // VULMON: CVE-2021-22384 // JVNDB: JVNDB-2021-010878 // CNNVD: CNNVD-202108-102 // NVD: CVE-2021-22384

PROBLEMTYPE DATA

problemtype:CWE-362

Trust: 1.1

problemtype:Race condition (CWE-362) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-380819 // JVNDB: JVNDB-2021-010878 // NVD: CVE-2021-22384

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-102

TYPE

competition condition problem

Trust: 0.6

sources: CNNVD: CNNVD-202108-102

PATCH

title:CVE-2021-22384url:https://consumer.huawei.com/en/support/bulletin/2021/6/

Trust: 0.8

title:Huawei Smartphone Repair measures for the competition condition problem loopholeurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159076

Trust: 0.6

sources: JVNDB: JVNDB-2021-010878 // CNNVD: CNNVD-202108-102

EXTERNAL IDS

db:NVDid:CVE-2021-22384

Trust: 3.4

db:JVNDBid:JVNDB-2021-010878

Trust: 0.8

db:CNNVDid:CNNVD-202108-102

Trust: 0.6

db:VULHUBid:VHN-380819

Trust: 0.1

db:VULMONid:CVE-2021-22384

Trust: 0.1

sources: VULHUB: VHN-380819 // VULMON: CVE-2021-22384 // JVNDB: JVNDB-2021-010878 // CNNVD: CNNVD-202108-102 // NVD: CVE-2021-22384

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2021/6/

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-22384

Trust: 0.8

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202107-0000001170634565

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/362.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-380819 // VULMON: CVE-2021-22384 // JVNDB: JVNDB-2021-010878 // CNNVD: CNNVD-202108-102 // NVD: CVE-2021-22384

SOURCES

db:VULHUBid:VHN-380819
db:VULMONid:CVE-2021-22384
db:JVNDBid:JVNDB-2021-010878
db:CNNVDid:CNNVD-202108-102
db:NVDid:CVE-2021-22384

LAST UPDATE DATE

2024-08-14T15:33:04.612000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-380819date:2021-12-09T00:00:00
db:VULMONid:CVE-2021-22384date:2021-08-06T00:00:00
db:JVNDBid:JVNDB-2021-010878date:2022-07-11T05:42:00
db:CNNVDid:CNNVD-202108-102date:2022-03-08T00:00:00
db:NVDid:CVE-2021-22384date:2021-12-09T17:55:10.140

SOURCES RELEASE DATE

db:VULHUBid:VHN-380819date:2021-08-02T00:00:00
db:VULMONid:CVE-2021-22384date:2021-08-02T00:00:00
db:JVNDBid:JVNDB-2021-010878date:2022-07-11T00:00:00
db:CNNVDid:CNNVD-202108-102date:2021-08-02T00:00:00
db:NVDid:CVE-2021-22384date:2021-08-02T17:15:13.723