Use-after-free in Huawei products - CVE-2021-37122
Published: October 11, 2021
Vulnerability identifier: #VU57183
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37122
CWE-ID: CWE-416
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error. A remote attacker on the local network can send a specially crafted packet and perform a denial of service (DoS) attack.
Affected software
Huawei CloudEngine 12800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
How to mitigate CVE-2021-37122
Install updates from vendor's website.
Huawei CloudEngine 12800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 5800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 6800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 7800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 5800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 6800 - addressed in versions V200R005SPH027, V200R019C10SPC800
Huawei CloudEngine 7800 - addressed in versions V200R005SPH027, V200R019C10SPC800