CVE-2021-22400: Input Validation
Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product include:OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1) and 10.1.0.202(C00E79R5P1).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22400?
The severity of CVE-2021-22400 is classified as high due to its potential to allow attackers to crash the system via malicious applications.
How do I fix CVE-2021-22400?
To fix CVE-2021-22400, users should update their Huawei OxfordS-AN00A devices to the latest firmware version that addresses this vulnerability.
Which devices are affected by CVE-2021-22400?
CVE-2021-22400 affects Huawei OxfordS-AN00A devices running specific firmware versions including 10.0.1.10, 10.0.1.105, and several others.
What can an attacker do with CVE-2021-22400?
An attacker exploiting CVE-2021-22400 can trick users into installing harmful apps that modify parameters, leading to a system crash.
Is there a workaround for CVE-2021-22400?
Currently, there is no official workaround for CVE-2021-22400 other than applying the available firmware updates to affected devices.