CVE-2021-22304
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Exploitability: 1.8 / Impact: 1.4
Source: NVD
Description
There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
Affected (1)
Products: Huawei: Taurus Al00a Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.0.1(c00e1r1p1) |
| Running on/with | Platform Versions |
|---|---|
Huawei Taurus Al00a | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.