Release of invalid pointer or reference in Huawei products - CVE-2021-40042
Published: January 20, 2022
Vulnerability identifier: #VU59870
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-40042
CWE-ID: CWE-763
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a release of invalid pointer in Huawei OptiX OSN 9800 U32 product. A remote authenticated attacker can send specially crafted messages and cause a denial of service condition in th target system.
Affected software
Huawei CloudEngine 12800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
Huawei CloudEngine 5800
Huawei CloudEngine 6800
Huawei CloudEngine 7800
How to mitigate CVE-2021-40042
Install updates from vendor's website.
Huawei CloudEngine 12800 - update to V200R019SPH007
Huawei CloudEngine 5800 - addressed in versions V200R019SPH007, V200R020SPH003
Huawei CloudEngine 6800 - addressed in versions V200R020SPH003, V200R020C00SPC600, V300R020SPH003
Huawei CloudEngine 7800 - update to V200R019SPH007
Huawei CloudEngine 5800 - addressed in versions V200R019SPH007, V200R020SPH003
Huawei CloudEngine 6800 - addressed in versions V200R020SPH003, V200R020C00SPC600, V300R020SPH003
Huawei CloudEngine 7800 - update to V200R019SPH007