CVE Vulnerabilities

CVE-2021-40045

Improper Verification of Cryptographic Signature

Published: Feb 09, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
EmuiHuawei11.0.0 (including)11.0.0 (including)
EmuiHuawei11.0.1 (including)11.0.1 (including)
EmuiHuawei12.0.0 (including)12.0.0 (including)
HarmonyosHuawei*2.0 (excluding)
Magic_uiHuawei4.0.0 (including)4.0.0 (including)

References