CVE-2021-37101
6.8
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.
Affected (2)
Products: Huawei: Ais Bw50 00 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0.6.2(h100sp10c00) |
| Running on/with | Platform Versions |
|---|---|
Huawei Ais Bw50 00 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.