CVE Vulnerabilities

CVE-2021-22299

Published: Feb 06, 2021 | Modified: Jul 12, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions 6.5.0,6.5.0.SPC100.B210,6.5.1.1.B010,6.5.1.1.B020,6.5.1.1.B030,6.5.1.1.B040,6.5.1.SPC100.B050,6.5.1.SPC101.B010,6.5.1.SPC101.B040,6.5.1.SPC200,6.5.1.SPC200.B010,6.5.1.SPC200.B030,6.5.1.SPC200.B040,6.5.1.SPC200.B050,6.5.1.SPC200.B060,6.5.1.SPC200.B070,6.5.1RC1.B060,6.5.1RC2.B020,6.5.1RC2.B030,6.5.1RC2.B040,6.5.1RC2.B050,6.5.1RC2.B060,6.5.1RC2.B070,6.5.1RC2.B080,6.5.1RC2.B090,6.5.RC2.B050,8.0.0,8.0.0-LCND81,8.0.0.SPC100,8.0.1,8.0.RC2,8.0.RC3,8.0.RC3.B041,8.0.RC3.SPC100; NFV_FusionSphere versions 6.5.1.SPC23,8.0.0.SPC12; SMC2.0 versions V600R019C00,V600R019C10; iMaster MAE-M versions MAE-TOOL(FusionSphereBasicTemplate_Euler_X86)V100R020C10SPC220.

Affected Software

Name Vendor Start Version End Version
Imaster_mae-m Huawei v100r020c10spc220 (including) v100r020c10spc220 (including)
Manageone Huawei 6.5.0 (including) 6.5.0 (including)
Manageone Huawei 6.5.0-rc2.b050 (including) 6.5.0-rc2.b050 (including)
Manageone Huawei 6.5.0-spc100.b210 (including) 6.5.0-spc100.b210 (including)
Manageone Huawei 6.5.1 (including) 6.5.1 (including)
Manageone Huawei 6.5.1-rc1.b060 (including) 6.5.1-rc1.b060 (including)
Manageone Huawei 6.5.1-rc2.b020 (including) 6.5.1-rc2.b020 (including)
Manageone Huawei 6.5.1-rc2.b030 (including) 6.5.1-rc2.b030 (including)
Manageone Huawei 6.5.1-rc2.b040 (including) 6.5.1-rc2.b040 (including)
Manageone Huawei 6.5.1-rc2.b050 (including) 6.5.1-rc2.b050 (including)
Manageone Huawei 6.5.1-rc2.b060 (including) 6.5.1-rc2.b060 (including)
Manageone Huawei 6.5.1-rc2.b070 (including) 6.5.1-rc2.b070 (including)
Manageone Huawei 6.5.1-rc2.b080 (including) 6.5.1-rc2.b080 (including)
Manageone Huawei 6.5.1-rc2.b090 (including) 6.5.1-rc2.b090 (including)
Manageone Huawei 6.5.1-spc100.b050 (including) 6.5.1-spc100.b050 (including)
Manageone Huawei 6.5.1-spc101.b010 (including) 6.5.1-spc101.b010 (including)
Manageone Huawei 6.5.1-spc101.b040 (including) 6.5.1-spc101.b040 (including)
Manageone Huawei 6.5.1-spc200 (including) 6.5.1-spc200 (including)
Manageone Huawei 6.5.1-spc200.b010 (including) 6.5.1-spc200.b010 (including)
Manageone Huawei 6.5.1-spc200.b030 (including) 6.5.1-spc200.b030 (including)
Manageone Huawei 6.5.1-spc200.b040 (including) 6.5.1-spc200.b040 (including)
Manageone Huawei 6.5.1-spc200.b050 (including) 6.5.1-spc200.b050 (including)
Manageone Huawei 6.5.1-spc200.b060 (including) 6.5.1-spc200.b060 (including)
Manageone Huawei 6.5.1-spc200.b070 (including) 6.5.1-spc200.b070 (including)
Manageone Huawei 6.5.1.1-b010 (including) 6.5.1.1-b010 (including)
Manageone Huawei 6.5.1.1-b020 (including) 6.5.1.1-b020 (including)
Manageone Huawei 6.5.1.1-b030 (including) 6.5.1.1-b030 (including)
Manageone Huawei 6.5.1.1-b040 (including) 6.5.1.1-b040 (including)
Manageone Huawei 8.0.0 (including) 8.0.0 (including)
Manageone Huawei 8.0.0-lcnd81 (including) 8.0.0-lcnd81 (including)
Manageone Huawei 8.0.0-rc2 (including) 8.0.0-rc2 (including)
Manageone Huawei 8.0.0-rc3 (including) 8.0.0-rc3 (including)
Manageone Huawei 8.0.0-rc3.b041 (including) 8.0.0-rc3.b041 (including)
Manageone Huawei 8.0.0-rc3.spc100 (including) 8.0.0-rc3.spc100 (including)
Manageone Huawei 8.0.0-spc100 (including) 8.0.0-spc100 (including)
Manageone Huawei 8.0.1 (including) 8.0.1 (including)
Network_functions_virtualization_fusionsphere Huawei 6.5.1-spc12 (including) 6.5.1-spc12 (including)
Network_functions_virtualization_fusionsphere Huawei 6.5.1-spc23 (including) 6.5.1-spc23 (including)

References