First published: Mon Mar 22 2021(Updated: )
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2700, S5700, S6700 , S7700, S9700, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei NIP6300 firmware | =v500r001c30 | |
Huawei NIP6300 firmware | =v500r001c60 | |
Huawei NIP6300 firmware | ||
Huawei NIP6600 | =v500r001c30 | |
Huawei NIP6600 firmware | ||
Huawei NIP6800 Firmware | =v500r001c60 | |
Huawei NIP6800 Firmware | ||
Huawei S12700 Firmware | =v200r007c01 | |
Huawei S12700 Firmware | =v200r007c01b102 | |
Huawei S12700 Firmware | =v200r008c00 | |
Huawei S12700 Firmware | =v200r010c00 | |
Huawei S12700 Firmware | =v200r010c00spc300 | |
Huawei S12700 Firmware | =v200r011c00 | |
Huawei S12700 Firmware | =v200r011c00spc100 | |
Huawei S12700 Firmware | =v200r011c10 | |
Huawei S12700 Firmware | ||
Huawei S1700 Firmware | =v200r009c00spc200 | |
Huawei S1700 Firmware | =v200r009c00spc500 | |
Huawei S1700 Firmware | =v200r010c00 | |
Huawei S1700 Firmware | =v200r010c00spc300 | |
Huawei S1700 Firmware | =v200r011c00 | |
Huawei S1700 Firmware | =v200r011c00spc100 | |
Huawei S1700 Firmware | =v200r011c10 | |
Huawei S1700 Firmware | ||
Huawei S2700 Firmware | =v200r008c00 | |
Huawei S2700 Firmware | =v200r010c00 | |
Huawei S2700 Firmware | =v200r010c00spc300 | |
Huawei S2700 Firmware | =v200r011c00 | |
Huawei S2700 Firmware | =v200r011c00spc100 | |
Huawei S2700 Firmware | =v200r011c10 | |
Huawei S2700 | ||
Huawei Campus S5700 firmware | =v200r008c00 | |
Huawei Campus S5700 firmware | =v200r010c00 | |
Huawei Campus S5700 firmware | =v200r010c00spc300 | |
Huawei Campus S5700 firmware | =v200r011c00 | |
Huawei Campus S5700 firmware | =v200r011c00spc100 | |
Huawei Campus S5700 firmware | =v200r011c10 | |
Huawei Campus S5700 firmware | =v200r011c10spc100 | |
Huawei S5700 Firmware | ||
Huawei 6700EI firmware | =v200r008c00 | |
Huawei 6700EI firmware | =v200r010c00 | |
Huawei 6700EI firmware | =v200r010c00spc300 | |
Huawei 6700EI firmware | =v200r011c00 | |
Huawei 6700EI firmware | =v200r011c00spc100 | |
Huawei 6700EI firmware | =v200r011c10 | |
Huawei 6700EI firmware | =v200r011c10spc100 | |
Huawei S6700 Firmware | ||
Huawei Campus S7700 firmware | =v200r008c00 | |
Huawei Campus S7700 firmware | =v200r010c00 | |
Huawei Campus S7700 firmware | =v200r010c00spc300 | |
Huawei Campus S7700 firmware | =v200r011c00 | |
Huawei Campus S7700 firmware | =v200r011c00spc100 | |
Huawei Campus S7700 firmware | =v200r011c10 | |
Huawei Campus S7700 | ||
Huawei LSW S9700 firmware | =v200r007c01 | |
Huawei LSW S9700 firmware | =v200r007c01b102 | |
Huawei LSW S9700 firmware | =v200r008c00 | |
Huawei LSW S9700 firmware | =v200r010c00 | |
Huawei LSW S9700 firmware | =v200r010c00spc300 | |
Huawei LSW S9700 firmware | =v200r011c00 | |
Huawei LSW S9700 firmware | =v200r011c00spc100 | |
Huawei LSW S9700 firmware | =v200r011c10 | |
Huawei 9700 Firmware | ||
Huawei USG6300E firmware | =v500r001c30 | |
Huawei USG6300E firmware | =v500r001c60 | |
Huawei Secospace USG6300 firmware | ||
Huawei Secospace USG6500 | =v500r001c30 | |
Huawei Secospace USG6500 | =v500r001c60 | |
Huawei Secospace USG6500 firmware | ||
Huawei Secospace USG6600 firmware | =v500r001c30 | |
Huawei Secospace USG6600 firmware | =v500r001c60 | |
Huawei Secospace USG6600 firmware | ||
Huawei USG9500 firmware | =v500r001c30 | |
Huawei USG9500 firmware | =v500r001c60 | |
Huawei Eudemon USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22321 has been classified with a high severity due to its potential to compromise system memory integrity.
To mitigate CVE-2021-22321, update the affected Huawei products to the latest firmware versions that address this vulnerability.
CVE-2021-22321 affects various Huawei firmware versions including NIP6300, NIP6600, NIP6800, and several models from the S series.
CVE-2021-22321 is a use-after-free vulnerability that can be exploited through specific malicious operations.
Yes, exploitation of CVE-2021-22321 can lead to service disruption by compromising normal system operations.