Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20220216-01-PRIESC
HistoryFeb 15, 2022 - 12:00 a.m.

Security Advisory - Privilege Escalation Vulnerability in Huawei Product

2022-02-1500:00:00
Huawei Technologies
www.huawei.com
23
security advisory
huawei
vulnerability
privilege escalation
cve
software updates

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

A Huawei product has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege. (Vulnerability ID: HWPSIRT-2021-49498)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2021-40046.

For products that have released software updates to fix this vulnerability, Huawei will release and update the Security Advisory at:

<http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220216-01-priesc-en&gt;

Affected configurations

Vulners
Node
huaweipcmanagerMatch11.1.1.95
VendorProductVersionCPE
huaweipcmanager11.1.1.95cpe:2.3:a:huawei:pcmanager:11.1.1.95:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

58.3%

Related for HUAWEI-SA-20220216-01-PRIESC