CVE Vulnerabilities

CVE-2021-37101

Published: Sep 09, 2021 | Modified: May 03, 2022
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.

Affected Software

Name Vendor Start Version End Version
Ais-bw50-00_firmware Huawei 9.0.6.2(h100sp10c00) (including) 9.0.6.2(h100sp10c00) (including)
Ais-bw50-00_firmware Huawei 9.0.6.2(h100sp15c00) (including) 9.0.6.2(h100sp15c00) (including)

References