CVE-2021-22398
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/08/2021
Last modified:
11/08/2021
Description
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected product versions include: Hulk-AL00C 9.1.1.201(C00E201R8P1);Jennifer-AN00C 10.1.1.171(C00E170R6P3);Jenny-AL10B 10.1.0.228(C00E220R5P1) and OxfordPL-AN10B 10.1.0.116(C00E110R2P1).
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:hulk-al00c_firmware:9.1.1.201\(c00e201r8p1\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:hulk-al00c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:jennifer-an00c_firmware:10.1.1.171\(c00e170r6p3\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:jennifer-an00c:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:jenny-al10b_firmware:10.1.0.228\(c00e220r5p1\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:jenny-al10b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:oxfordpl-an10b_firmware:10.1.0.116\(c00e110r2p1\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:oxfordpl-an10b:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page