First published: Wed Feb 09 2022(Updated: )
There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMUI 5.0 | =11.0.0 | |
EMUI 5.0 | =11.0.1 | |
EMUI 5.0 | =12.0.0 | |
HarmonyOS | <2.0 | |
Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40045 is considered a significant vulnerability due to its potential impact on service confidentiality.
To mitigate CVE-2021-40045, users should apply the latest firmware updates provided by Huawei for affected software versions.
CVE-2021-40045 affects Huawei EMUI versions 11.0.0, 11.0.1, 12.0.0, HarmonyOS versions below 2.0, and Huawei Magic UI 4.0.0.
Yes, CVE-2021-40045 can potentially be exploited remotely through the recovery mode during system upgrades.
Exploitation of CVE-2021-40045 may lead to unauthorized access and compromise of sensitive service data.