CVE-2021-22321
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
22/03/2021
Last modified:
24/03/2021
Description
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2700, S5700, S6700 , S7700, S9700, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:nip6300_firmware:v500r001c30:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:nip6300_firmware:v500r001c60:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:nip6300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:nip6600_firmware:v500r001c30:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:nip6600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:nip6800_firmware:v500r001c60:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:nip6800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r007c01:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r007c01b102:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r008c00:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r010c00:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r010c00spc300:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r011c00:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r011c00spc100:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:s12700_firmware:v200r011c10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



