Lucene search

K
nvd[email protected]NVD:CVE-2021-22440
HistoryJul 13, 2021 - 12:15 p.m.

CVE-2021-22440

2021-07-1312:15:09
CWE-22
web.nvd.nist.gov
5
path traversal vulnerability
huawei products
external input
crafted filename
parent directory
restricted directory

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

30.3%

There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename. Affected product versions include:HUAWEI Mate 20 9.0.0.195(C01E195R2P1), 9.1.0.139(C00E133R3P1);HUAWEI Mate 20 Pro 9.0.0.187(C432E10R1P16), 9.0.0.188(C185E10R2P1), 9.0.0.245(C10E10R2P1), 9.0.0.266(C432E10R1P16), 9.0.0.267(C636E10R2P1), 9.0.0.268(C635E12R1P16), 9.0.0.278(C185E10R2P1); Hima-L29C 9.0.0.105(C10E9R1P16), 9.0.0.105(C185E9R1P16), 9.0.0.105(C636E9R1P16); Laya-AL00EP 9.1.0.139(C786E133R3P1); OxfordS-AN00A 10.1.0.223(C00E210R5P1); Tony-AL00B 9.1.0.257(C00E222R2P1).

Affected configurations

Nvd
Node
huaweimate_20_firmwareMatch9.0.0.195\(c01e195r2p1\)
OR
huaweimate_20_firmwareMatch9.1.0.139\(c00e133r3p1\)
AND
huaweimate_20Match-
Node
huaweimate_20_pro_firmwareMatch9.0.0.187\(c432e10r1p16\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.188\(c185e10r2p1\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.245\(c10e10r2p1\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.266\(c432e10r1p16\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.267\(c636e10r2p1\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.268\(c635e12r1p16\)
OR
huaweimate_20_pro_firmwareMatch9.0.0.278\(c185e10r2p1\)
AND
huaweimate_20_proMatch-
Node
huaweihima-l29c_firmwareMatch9.0.0.105\(c10e9r1p16\)
OR
huaweihima-l29c_firmwareMatch9.0.0.105\(c185e9r1p16\)
OR
huaweihima-l29c_firmwareMatch9.0.0.105\(c636e9r1p16\)
AND
huaweihima-l29cMatch-
Node
huaweilaya-al00ep_firmwareMatch9.1.0.139\(c786e133r3p1\)
AND
huaweilaya-al00epMatch-
Node
huaweioxfords-an00a_firmwareMatch10.1.0.223\(c00e210r5p1\)
AND
huaweioxfords-an00aMatch-
Node
huaweitony-al00b_firmwareMatch9.1.0.257\(c00e222r2p1\)
AND
huaweitony-al00bMatch-
VendorProductVersionCPE
huaweimate_20_firmware9.0.0.195(c01e195r2p1)cpe:2.3:o:huawei:mate_20_firmware:9.0.0.195\(c01e195r2p1\):*:*:*:*:*:*:*
huaweimate_20_firmware9.1.0.139(c00e133r3p1)cpe:2.3:o:huawei:mate_20_firmware:9.1.0.139\(c00e133r3p1\):*:*:*:*:*:*:*
huaweimate_20-cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.187(c432e10r1p16)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.187\(c432e10r1p16\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.188(c185e10r2p1)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.188\(c185e10r2p1\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.245(c10e10r2p1)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.245\(c10e10r2p1\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.266(c432e10r1p16)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.266\(c432e10r1p16\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.267(c636e10r2p1)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.267\(c636e10r2p1\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.268(c635e12r1p16)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.268\(c635e12r1p16\):*:*:*:*:*:*:*
huaweimate_20_pro_firmware9.0.0.278(c185e10r2p1)cpe:2.3:o:huawei:mate_20_pro_firmware:9.0.0.278\(c185e10r2p1\):*:*:*:*:*:*:*
Rows per page:
1-10 of 211

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.6

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

30.3%

Related for NVD:CVE-2021-22440