← Back

CVE-2021-37127

nvd nist
Published: Oct 27, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.

Affected (16)

2 products
Imanager Neteco 6000 Firmware
Imanager Neteco Firmware
Configuration A
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v600r010c00cp2001
Version v600r010c00cp2002
Version v600r010c00spc100
Version v600r010c00spc110
Version v600r010c00spc120
Version v600r010c00spc200
Version v600r010c00spc210
Version v600r010c00spc300
Running on/withPlatform Versions
Huawei
Imanager Neteco 6000
All versions
Configuration B
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Huawei
Version v600r009c00spc100
Version v600r009c00spc110
Version v600r009c00spc120
Version v600r009c00spc190
Version v600r009c00spc200
Version v600r009c00spc201
Version v600r009c00spc202
Version v600r009c00spc210
Running on/withPlatform Versions
Huawei
Imanager Neteco
All versions

Timeline

No history available yet.