ID

VAR-202112-0285


CVE

CVE-2021-37040


TITLE

plural  Huawei  Argument insertion or modification vulnerability in smartphone products

Trust: 0.8

sources: JVNDB: JVNDB-2021-015891

DESCRIPTION

There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting. plural Huawei Smartphone products contain an argument injection or modification vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS. No detailed vulnerability details were provided at this time

Trust: 1.71

sources: NVD: CVE-2021-37040 // JVNDB: JVNDB-2021-015891 // VULHUB: VHN-398873

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:11.0.0

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:4.0.0

Trust: 1.0

vendor:huaweimodel:harmonyosscope:ltversion:2.0

Trust: 1.0

vendor:huaweimodel:harmonyosscope: - version: -

Trust: 0.8

vendor:huaweimodel:magic uiscope: - version: -

Trust: 0.8

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-015891 // NVD: CVE-2021-37040

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-37040
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-37040
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202109-2050
value: CRITICAL

Trust: 0.6

VULHUB: VHN-398873
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-37040
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-398873
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-37040
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-37040
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-398873 // JVNDB: JVNDB-2021-015891 // CNNVD: CNNVD-202109-2050 // NVD: CVE-2021-37040

PROBLEMTYPE DATA

problemtype:CWE-88

Trust: 1.1

problemtype:Insert or change arguments (CWE-88) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-74

Trust: 0.1

sources: VULHUB: VHN-398873 // JVNDB: JVNDB-2021-015891 // NVD: CVE-2021-37040

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-2050

TYPE

parameter injection

Trust: 0.6

sources: CNNVD: CNNVD-202109-2050

PATCH

title:Parameter injection vulnerability in some HUAWEI phonesurl:https://device.harmonyos.com/en/docs/security/update/security-bulletins-202109-0000001196270727

Trust: 0.8

title:Huawei HarmonyOS Repair measures for injecting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=173803

Trust: 0.6

sources: JVNDB: JVNDB-2021-015891 // CNNVD: CNNVD-202109-2050

EXTERNAL IDS

db:NVDid:CVE-2021-37040

Trust: 3.3

db:JVNDBid:JVNDB-2021-015891

Trust: 0.8

db:CNNVDid:CNNVD-202109-2050

Trust: 0.6

db:CNVDid:CNVD-2022-08329

Trust: 0.1

db:VULHUBid:VHN-398873

Trust: 0.1

sources: VULHUB: VHN-398873 // JVNDB: JVNDB-2021-015891 // CNNVD: CNNVD-202109-2050 // NVD: CVE-2021-37040

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2021/9/

Trust: 1.7

url:https://device.harmonyos.com/en/docs/security/update/security-bulletins-202109-0000001196270727

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-37040

Trust: 0.8

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202109-0000001196270727

Trust: 0.6

sources: VULHUB: VHN-398873 // JVNDB: JVNDB-2021-015891 // CNNVD: CNNVD-202109-2050 // NVD: CVE-2021-37040

SOURCES

db:VULHUBid:VHN-398873
db:JVNDBid:JVNDB-2021-015891
db:CNNVDid:CNNVD-202109-2050
db:NVDid:CVE-2021-37040

LAST UPDATE DATE

2024-08-14T15:01:15.769000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-398873date:2022-07-12T00:00:00
db:JVNDBid:JVNDB-2021-015891date:2022-12-01T07:34:00
db:CNNVDid:CNNVD-202109-2050date:2022-07-14T00:00:00
db:NVDid:CVE-2021-37040date:2022-07-12T17:42:04.277

SOURCES RELEASE DATE

db:VULHUBid:VHN-398873date:2021-12-08T00:00:00
db:JVNDBid:JVNDB-2021-015891date:2022-12-01T00:00:00
db:CNNVDid:CNNVD-202109-2050date:2021-09-05T00:00:00
db:NVDid:CVE-2021-37040date:2021-12-08T15:15:09.267