First published: Wed Oct 27 2021(Updated: )
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC500,V200R019C10SPC200,V200R020C00,V200R020C10;S1700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S2700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S5700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600,V200R019C00SPC500;S6700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S7700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600;S9700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;USG9500 V500R005C00,V500R005C20.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei IPS firmware | =v500r005c00 | |
Huawei IPS firmware | =v500r005c20 | |
Huawei IPS Module firmware | ||
Huawei NGFW Module firmware | =v500r005c00 | |
Huawei NGFW Module | ||
Huawei NIP6600 | =v500r005c00 | |
Huawei NIP6600 | =v500r005c20 | |
Huawei NIP6600 firmware | ||
Huawei S12700 Firmware | =v200r010c00spc600 | |
Huawei S12700 Firmware | =v200r011c10spc500 | |
Huawei S12700 Firmware | =v200r011c10spc600 | |
Huawei S12700 Firmware | =v200r013c00spc500 | |
Huawei S12700 Firmware | =v200r019c00spc200 | |
Huawei S12700 Firmware | =v200r019c00spc500 | |
Huawei S12700 Firmware | =v200r019c10spc200 | |
Huawei S12700 Firmware | =v200r020c00 | |
Huawei S12700 Firmware | =v200r020c10 | |
Huawei S12700 Firmware | ||
Huawei S1700 Firmware | =v200r010c00spc600 | |
Huawei S1700 Firmware | =v200r011c10spc500 | |
Huawei S1700 Firmware | =v200r011c10spc600 | |
Huawei S1700 Firmware | ||
Huawei S2700 Firmware | =v200r010c00spc600 | |
Huawei S2700 Firmware | =v200r011c10spc500 | |
Huawei S2700 Firmware | =v200r011c10spc600 | |
Huawei S2700 | ||
Huawei Campus S5700 firmware | =v200r010c00spc600 | |
Huawei Campus S5700 firmware | =v200r010c00spc700 | |
Huawei Campus S5700 firmware | =v200r011c10spc500 | |
Huawei Campus S5700 firmware | =v200r011c10spc600 | |
Huawei Campus S5700 firmware | =v200r019c00spc500 | |
Huawei S5700 Firmware | ||
Huawei 6700EI firmware | =v200r010c00spc600 | |
Huawei 6700EI firmware | =v200r011c10spc500 | |
Huawei 6700EI firmware | =v200r011c10spc600 | |
Huawei S6700 Firmware | ||
Huawei Campus S7700 firmware | =v200r010c00spc600 | |
Huawei Campus S7700 firmware | =v200r010c00spc700 | |
Huawei Campus S7700 firmware | =v200r011c10spc500 | |
Huawei Campus S7700 firmware | =v200r011c10spc600 | |
Huawei Campus S7700 | ||
Huawei LSW S9700 firmware | =v200r010c00spc600 | |
Huawei LSW S9700 firmware | =v200r011c10spc500 | |
Huawei LSW S9700 firmware | =v200r011c10spc600 | |
Huawei 9700 Firmware | ||
Huawei USG9500 firmware | =v500r005c00 | |
Huawei USG9500 firmware | =v500r005c20 | |
Huawei Eudemon USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37129.
The severity of CVE-2021-37129 is high with a score of 7.5.
Several Huawei products, including Huawei IPS Module, Huawei NGFW Module, Huawei Nip6600, Huawei S12700, Huawei S1700, Huawei S2700, Huawei S5700, Huawei S6700, Huawei S7700, Huawei S9700, and Huawei USG9500, are affected by CVE-2021-37129.
CVE-2021-37129 is caused by an out of bounds write vulnerability in some Huawei products that is caused by a function of a module not properly verifying input parameters.
Successful exploitation of CVE-2021-37129 could cause an out of bounds write leading to a denial of service condition.
It is recommended to apply the necessary security patches provided by Huawei to mitigate CVE-2021-37129.