CVE Vulnerabilities

CVE-2021-40045

Improper Verification of Cryptographic Signature

Published: Feb 09, 2022 | Modified: Feb 16, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 11.0.0 (including) 11.0.0 (including)
Emui Huawei 11.0.1 (including) 11.0.1 (including)
Emui Huawei 12.0.0 (including) 12.0.0 (including)
Harmonyos Huawei * 2.0 (excluding)
Magic_ui Huawei 4.0.0 (including) 4.0.0 (including)

References