CVE-2021-37129Out-of-bounds Write in Huawei IPS Module Firmware

Severity
7.5HIGHNVD
EPSS
0.2%
top 60.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 24

Description

There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages11 packages

NVDhuawei/ips_module_firmwarev500r005c00, v500r005c20+1
NVDhuawei/s1700_firmwarev200r010c00spc600, v200r011c10spc500, v200r011c10spc600+2
NVDhuawei/s2700_firmwarev200r010c00spc600, v200r011c10spc500, v200r011c10spc600+2
NVDhuawei/s5700_firmware5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-53hh-mvr7-x3hp: There is an out of bounds write vulnerability in some Huawei products2022-05-24
CVEList
CVE-2021-37129: There is an out of bounds write vulnerability in some Huawei products2021-10-27
CVE-2021-37129 — Out-of-bounds Write in Huawei | cvebase