CVE-2021-37129
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC500,V200R019C10SPC200,V200R020C00,V200R020C10;S1700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S2700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S5700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600,V200R019C00SPC500;S6700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S7700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600;S9700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;USG9500 V500R005C00,V500R005C20.
Affected (37)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ips Module | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ngfw Module | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Nip6600 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S12700 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S1700 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S2700 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S5700 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S6700 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S7700 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r010c00spc600 |
| Running on/with | Platform Versions |
|---|---|
Huawei S9700 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r005c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Usg9500 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.