CVE-2021-22397: Input Validation
There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22397?
CVE-2021-22397 is a privilege escalation vulnerability in Huawei ManageOne 8.0.0.
How does CVE-2021-22397 affect Huawei ManageOne?
CVE-2021-22397 affects Huawei ManageOne 8.0.0 by allowing attackers to exploit external parameters of certain files, leading to privilege escalation attacks and potential compromise of normal service.
What is the severity of CVE-2021-22397?
The severity of CVE-2021-22397 is medium with a CVSS score of 6.7.
How can attackers exploit CVE-2021-22397?
Attackers can exploit CVE-2021-22397 by manipulating the external parameters of specific files in Huawei ManageOne 8.0.0 to gain elevated privileges.
Is there a fix for CVE-2021-22397?
To fix CVE-2021-22397, Huawei ManageOne users should apply the latest security patch provided by Huawei.