ID

VAR-202201-1311


CVE

CVE-2021-40042


TITLE

plural  Huawei  Invalid Pointer and Free Reference Vulnerabilities in Products

Trust: 0.8

sources: JVNDB: JVNDB-2022-004566

DESCRIPTION

There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal. Affected product versions include: CloudEngine 12800 V200R019C10SPC800, V200R019C10SPC900; CloudEngine 5800 V200R019C10SPC800, V200R020C00SPC600; CloudEngine 6800 versions V200R019C10SPC800, V200R019C10SPC900, V200R020C00SPC600, V300R020C00SPC200; CloudEngine 7800 V200R019C10SPC800. plural Huawei The product contains an invalid pointer and reference freeing vulnerability.Service operation interruption (DoS) It may be in a state. Huawei CloudEngine 12800, etc. are all products of China's Huawei (Huawei). Huawei CloudEngine 12800 is a 12800 series data center switch. Huawei Cloudengine 5800 is a 5800 series data center switch. A buffer overflow vulnerability exists in many Huawei products. The vulnerability is caused by insufficient validation of certain parameters in the message

Trust: 2.16

sources: NVD: CVE-2021-40042 // JVNDB: JVNDB-2022-004566 // CNVD: CNVD-2022-17397

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-17397

AFFECTED PRODUCTS

vendor:huaweimodel:cloudengine 12800scope:eqversion:v200r019c10spc800

Trust: 1.0

vendor:huaweimodel:cloudengine 5800scope:eqversion:v200r020c00spc600

Trust: 1.0

vendor:huaweimodel:cloudengine 6800scope:eqversion:v200r019c10spc900

Trust: 1.0

vendor:huaweimodel:cloudengine 6800scope:eqversion:v200r019c10spc800

Trust: 1.0

vendor:huaweimodel:cloudengine 7800scope:eqversion:v200r019c10spc800

Trust: 1.0

vendor:huaweimodel:cloudengine 5800scope:eqversion:v200r019c10spc800

Trust: 1.0

vendor:huaweimodel:cloudengine 6800scope:eqversion:v200r020c00spc600

Trust: 1.0

vendor:huaweimodel:cloudengine 12800scope:eqversion:v200r019c10spc900

Trust: 1.0

vendor:huaweimodel:cloudengine 6800scope:eqversion:v300r020c00spc200

Trust: 1.0

vendor:huaweimodel:cloudengine 12800scope: - version: -

Trust: 0.8

vendor:huaweimodel:cloudengine 5800scope: - version: -

Trust: 0.8

vendor:huaweimodel:cloudengine 7800scope: - version: -

Trust: 0.8

vendor:huaweimodel:cloudengine 6800scope: - version: -

Trust: 0.8

vendor:huaweimodel:cloudengine v200r019c10spc800scope:eqversion:12800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r019c10spc900scope:eqversion:12800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r019c10spc800scope:eqversion:5800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r020c00spc600scope:eqversion:5800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r019c10spc800scope:eqversion:6800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r019c10spc900scope:eqversion:6800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r020c00spc600scope:eqversion:6800

Trust: 0.6

vendor:huaweimodel:cloudengine v300r020c00spc200scope:eqversion:6800

Trust: 0.6

vendor:huaweimodel:cloudengine v200r019c10spc800scope:eqversion:7800

Trust: 0.6

sources: CNVD: CNVD-2022-17397 // JVNDB: JVNDB-2022-004566 // NVD: CVE-2021-40042

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-40042
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-40042
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2022-17397
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202201-1777
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2021-40042
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2022-17397
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-40042
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-40042
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-17397 // JVNDB: JVNDB-2022-004566 // CNNVD: CNNVD-202201-1777 // NVD: CVE-2021-40042

PROBLEMTYPE DATA

problemtype:CWE-763

Trust: 1.0

problemtype:Freeing invalid pointers and references (CWE-763) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-004566 // NVD: CVE-2021-40042

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202201-1777

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202201-1777

PATCH

title:huawei-sa-20220112-01-invalidurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220112-01-invalid-en

Trust: 0.8

title:Patch for Buffer Overflow Vulnerability in Several Huawei Products (CNVD-2022-17397)url:https://www.cnvd.org.cn/patchInfo/show/323711

Trust: 0.6

title:Huawei Repair measures for buffer errors and vulnerabilities in many productsurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=178973

Trust: 0.6

sources: CNVD: CNVD-2022-17397 // JVNDB: JVNDB-2022-004566 // CNNVD: CNNVD-202201-1777

EXTERNAL IDS

db:NVDid:CVE-2021-40042

Trust: 3.8

db:JVNDBid:JVNDB-2022-004566

Trust: 0.8

db:CNVDid:CNVD-2022-17397

Trust: 0.6

db:CS-HELPid:SB2022012005

Trust: 0.6

db:CNNVDid:CNNVD-202201-1777

Trust: 0.6

sources: CNVD: CNVD-2022-17397 // JVNDB: JVNDB-2022-004566 // CNNVD: CNNVD-202201-1777 // NVD: CVE-2021-40042

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2021-40042

Trust: 2.0

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220112-01-invalid-en

Trust: 1.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012005

Trust: 0.6

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20220112-01-invalid-cn

Trust: 0.6

sources: CNVD: CNVD-2022-17397 // JVNDB: JVNDB-2022-004566 // CNNVD: CNNVD-202201-1777 // NVD: CVE-2021-40042

CREDITS

The vulnerability was discovered by Huawei internal testing.

Trust: 0.6

sources: CNNVD: CNNVD-202201-1777

SOURCES

db:CNVDid:CNVD-2022-17397
db:JVNDBid:JVNDB-2022-004566
db:CNNVDid:CNNVD-202201-1777
db:NVDid:CVE-2021-40042

LAST UPDATE DATE

2024-11-23T22:40:37.235000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-17397date:2022-03-08T00:00:00
db:JVNDBid:JVNDB-2022-004566date:2023-04-18T08:19:00
db:CNNVDid:CNNVD-202201-1777date:2022-03-10T00:00:00
db:NVDid:CVE-2021-40042date:2024-11-21T06:23:26.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-17397date:2022-03-08T00:00:00
db:JVNDBid:JVNDB-2022-004566date:2023-04-18T00:00:00
db:CNNVDid:CNNVD-202201-1777date:2022-01-19T00:00:00
db:NVDid:CVE-2021-40042date:2022-01-31T16:15:09.970