First published: Wed Oct 27 2021(Updated: )
There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this vulnerability. Successful exploitation may cause the service abnormal. Affected product versions include:CloudEngine 12800 V200R005C10SPC800,V200R019C00SPC800;CloudEngine 5800 V200R005C10SPC800,V200R019C00SPC800;CloudEngine 6800 V200R005C10SPC800,V200R005C20SPC800,V200R019C00SPC800;CloudEngine 7800 V200R005C10SPC800,V200R019C00SPC800.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Cloudengine 12800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 12800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 12800 | ||
Huawei Cloudengine 5800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 5800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 5800 | ||
Huawei Cloudengine 6800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r005c20spc800 | |
Huawei Cloudengine 6800 Firmware | =v200r019c00spc800 | |
Huawei CloudEngine 6800 | ||
Huawei Cloudengine 7800 Firmware | =v200r005c10spc800 | |
Huawei Cloudengine 7800 Firmware | =v200r019c00spc800 | |
Huawei Cloudengine 7800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37122.
The severity of CVE-2021-37122 is medium with a CVSS score of 6.5.
The affected products include CloudEngine 12800 V200R005C10SPC800, V200R019C00SPC800, and CloudEngine 5800 V20.
Successful exploitation of CVE-2021-37122 may cause the service to become abnormal.
You can find more information about CVE-2021-37122 on the Huawei PSIRT security advisory page.