CVE-2021-40045Improper Verification of Cryptographic Signature in Huawei Harmonyos

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateFeb 11

Description

There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode.Successful exploitation of this vulnerability may affect service confidentiality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDhuawei/harmonyos< 2.0
CVEListV5huawei/emui2.0
NVDhuawei/emui11.0.0, 11.0.1, 12.0.0+2
CVEListV5huawei/magic_ui11.0.0, 11.0.1, 12.0.0+2
NVDhuawei/magic_ui4.0.0

🔴Vulnerability Details

2
GHSA
GHSA-crq4-6fjx-j758: There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode2022-02-11
CVEList
CVE-2021-40045: There is a vulnerability of signature verification mechanism failure in system upgrade through recovery mode2022-02-09
CVE-2021-40045 — Huawei Harmonyos vulnerability | cvebase