CVE-2021-40010Out-of-bounds Write in Huawei Emui

Severity
9.8CRITICALNVD
EPSS
0.8%
top 25.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malicious code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDhuawei/emui6 versions+5
NVDhuawei/magic_ui4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-f5rf-7v92-j3pg: The bone voice ID trusted application (TA) has a heap overflow vulnerability2022-01-11
CVEList
CVE-2021-40010: The bone voice ID TA has a heap overflow vulnerability2022-01-07
CVE-2021-40010 — Out-of-bounds Write in Huawei Emui | cvebase