CVE-2021-22304: Use After Free
There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22304?
CVE-2021-22304 is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1) firmware.
How does CVE-2021-22304 impact Huawei Taurus-AL00A firmware?
CVE-2021-22304 allows attackers to send specific messages to an affected module, leading to module crash or compromise.
What is the severity of CVE-2021-22304?
CVE-2021-22304 has a severity rating of low (3.3).
How can attackers exploit CVE-2021-22304?
Attackers can exploit CVE-2021-22304 by sending specific messages to the affected module.
Is Huawei Taurus-AL00A vulnerable to CVE-2021-22304?
Yes, Huawei Taurus-AL00A firmware version 10.0.0.1 (C00E1R1P1) is vulnerable to CVE-2021-22304.