First published: Sat Feb 06 2021(Updated: )
There is an out-of-bound read vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module does not verify the some input. Attackers can exploit this vulnerability by sending malicious input through specific app. This could cause out-of-bound, compromising normal service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus-al00a Firmware | =10.0.0.1\(c00e1r1p1\) | |
Huawei Taurus-al00a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22302 is an out-of-bound read vulnerability in Huawei Taurus-AL00A 10.0.0.1(C00E1R1P1) firmware.
CVE-2021-22302 allows attackers to exploit the out-of-bound read vulnerability in Huawei Taurus-AL00A 10.0.0.1(C00E1R1P1) firmware by sending malicious input through a specific app, compromising normal service.
CVE-2021-22302 has a severity rating of 7.1, which is considered high.
To fix CVE-2021-22302, it is recommended to update the Huawei Taurus-AL00A firmware to a version that addresses the vulnerability.
More information about CVE-2021-22302 can be found in Huawei's security advisory at https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-01-smartphone-en.