ID

VAR-202108-2206


CVE

CVE-2021-22388


TITLE

Huawei  Integer overflow vulnerability in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2021-010874

DESCRIPTION

There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed. Huawei An integer overflow vulnerability exists in smartphones.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.8

sources: NVD: CVE-2021-22388 // JVNDB: JVNDB-2021-010874 // VULHUB: VHN-380823 // VULMON: CVE-2021-22388

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:11.0.0

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:4.0.0

Trust: 1.0

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

vendor:huaweimodel:magic uiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-010874 // NVD: CVE-2021-22388

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22388
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-22388
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202108-105
value: CRITICAL

Trust: 0.6

VULHUB: VHN-380823
value: HIGH

Trust: 0.1

VULMON: CVE-2021-22388
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-22388
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-380823
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-22388
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-22388
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-380823 // VULMON: CVE-2021-22388 // JVNDB: JVNDB-2021-010874 // CNNVD: CNNVD-202108-105 // NVD: CVE-2021-22388

PROBLEMTYPE DATA

problemtype:CWE-190

Trust: 1.1

problemtype:Integer overflow or wraparound (CWE-190) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-380823 // JVNDB: JVNDB-2021-010874 // NVD: CVE-2021-22388

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202108-105

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202108-105

PATCH

title:CVE-2021-22388url:https://consumer.huawei.com/en/support/bulletin/2021/6/

Trust: 0.8

title:Huawei Smartphone Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=159077

Trust: 0.6

sources: JVNDB: JVNDB-2021-010874 // CNNVD: CNNVD-202108-105

EXTERNAL IDS

db:NVDid:CVE-2021-22388

Trust: 3.4

db:JVNDBid:JVNDB-2021-010874

Trust: 0.8

db:CNNVDid:CNNVD-202108-105

Trust: 0.6

db:VULHUBid:VHN-380823

Trust: 0.1

db:VULMONid:CVE-2021-22388

Trust: 0.1

sources: VULHUB: VHN-380823 // VULMON: CVE-2021-22388 // JVNDB: JVNDB-2021-010874 // CNNVD: CNNVD-202108-105 // NVD: CVE-2021-22388

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2021/6/

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2021-22388

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/190.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-380823 // VULMON: CVE-2021-22388 // JVNDB: JVNDB-2021-010874 // CNNVD: CNNVD-202108-105 // NVD: CVE-2021-22388

SOURCES

db:VULHUBid:VHN-380823
db:VULMONid:CVE-2021-22388
db:JVNDBid:JVNDB-2021-010874
db:CNNVDid:CNNVD-202108-105
db:NVDid:CVE-2021-22388

LAST UPDATE DATE

2024-08-14T15:11:48.590000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-380823date:2021-12-09T00:00:00
db:VULMONid:CVE-2021-22388date:2021-08-06T00:00:00
db:JVNDBid:JVNDB-2021-010874date:2022-07-11T05:34:00
db:CNNVDid:CNNVD-202108-105date:2021-08-09T00:00:00
db:NVDid:CVE-2021-22388date:2021-12-09T17:55:10.150

SOURCES RELEASE DATE

db:VULHUBid:VHN-380823date:2021-08-02T00:00:00
db:VULMONid:CVE-2021-22388date:2021-08-02T00:00:00
db:JVNDBid:JVNDB-2021-010874date:2022-07-11T00:00:00
db:CNNVDid:CNNVD-202108-105date:2021-08-02T00:00:00
db:NVDid:CVE-2021-22388date:2021-08-02T17:15:13.833