CVE-2021-40037Type Confusion in Huawei Harmonyos

CWE-843Type Confusion3 documents3 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateJan 11

Description

There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDhuawei/harmonyos< 2.0
CVEListV5huawei/emui6 versions+5
NVDhuawei/emui6 versions+5
CVEListV5huawei/magic_ui4 versions+3
NVDhuawei/magic_ui4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-gg65-289v-hp7m: There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones2022-01-11
CVEList
CVE-2021-40037: There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones2022-01-07
CVE-2021-40037 — Type Confusion in Huawei Harmonyos | cvebase