ID

VAR-202111-1584


CVE

CVE-2021-37033


TITLE

Huawei  Injection Vulnerability in Smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2021-015553

DESCRIPTION

There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. Huawei Smartphones have an injection vulnerability.Service operation interruption (DoS) It may be in a state. Huawei Emui is a mobile operating system developed based on Android. Magic Ui is a mobile operating system developed based on Android. Huawei Emui and Magic UI have injection attack vulnerabilities

Trust: 1.71

sources: NVD: CVE-2021-37033 // JVNDB: JVNDB-2021-015553 // VULHUB: VHN-398866

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:11.0.0

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:4.0.0

Trust: 1.0

vendor:huaweimodel:magic uiscope: - version: -

Trust: 0.8

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-015553 // NVD: CVE-2021-37033

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-37033
value: HIGH

Trust: 1.0

NVD: CVE-2021-37033
value: HIGH

Trust: 0.8

CNNVD: CNNVD-202111-1902
value: HIGH

Trust: 0.6

VULHUB: VHN-398866
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-37033
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-398866
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-37033
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-37033
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-398866 // JVNDB: JVNDB-2021-015553 // CNNVD: CNNVD-202111-1902 // NVD: CVE-2021-37033

PROBLEMTYPE DATA

problemtype:CWE-74

Trust: 1.1

problemtype:injection (CWE-74) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-398866 // JVNDB: JVNDB-2021-015553 // NVD: CVE-2021-37033

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202111-1902

TYPE

injection

Trust: 0.6

sources: CNNVD: CNNVD-202111-1902

PATCH

title:HUAWEI EMUI/Magic UI security updates August 2021url:https://consumer.huawei.com/en/support/bulletin/2021/8/

Trust: 0.8

title:Huawei Emui Repair measures for injecting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=172197

Trust: 0.6

sources: JVNDB: JVNDB-2021-015553 // CNNVD: CNNVD-202111-1902

EXTERNAL IDS

db:NVDid:CVE-2021-37033

Trust: 3.3

db:JVNDBid:JVNDB-2021-015553

Trust: 0.8

db:CNNVDid:CNNVD-202111-1902

Trust: 0.6

db:CNVDid:CNVD-2021-102864

Trust: 0.1

db:VULHUBid:VHN-398866

Trust: 0.1

sources: VULHUB: VHN-398866 // JVNDB: JVNDB-2021-015553 // CNNVD: CNNVD-202111-1902 // NVD: CVE-2021-37033

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2021/8/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-37033

Trust: 1.4

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202109-0000001196270727

Trust: 0.6

sources: VULHUB: VHN-398866 // JVNDB: JVNDB-2021-015553 // CNNVD: CNNVD-202111-1902 // NVD: CVE-2021-37033

SOURCES

db:VULHUBid:VHN-398866
db:JVNDBid:JVNDB-2021-015553
db:CNNVDid:CNNVD-202111-1902
db:NVDid:CVE-2021-37033

LAST UPDATE DATE

2024-08-14T14:37:49.104000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-398866date:2021-12-09T00:00:00
db:JVNDBid:JVNDB-2021-015553date:2022-11-24T06:21:00
db:CNNVDid:CNNVD-202111-1902date:2021-12-01T00:00:00
db:NVDid:CVE-2021-37033date:2021-12-09T17:57:49.643

SOURCES RELEASE DATE

db:VULHUBid:VHN-398866date:2021-11-23T00:00:00
db:JVNDBid:JVNDB-2021-015553date:2022-11-24T00:00:00
db:CNNVDid:CNNVD-202111-1902date:2021-11-23T00:00:00
db:NVDid:CVE-2021-37033date:2021-11-23T16:15:09.833