VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202112-0245 CVE-2021-37070 Huawei  Out-of-Bounds Read Vulnerability in Smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to process crash. Huawei Smartphones contain an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202112-0222 CVE-2021-37100 Huawei  Authentication Vulnerability in Smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed. Huawei Smartphones have an authentication vulnerability.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a component of the product that does not effectively authenticate user identities
VAR-202112-0228 CVE-2021-37090 Huawei  Out-of-bounds reading vulnerability in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to process crash. Huawei Smartphone products contain an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. Huawei HarmonyOS has security vulnerabilities
VAR-202112-0248 CVE-2021-37066 Huawei  Out-of-Bounds Read Vulnerability in Smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to process crash. Huawei Smartphones contain an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202112-0347 CVE-2021-37053 plural  Huawei  Vulnerabilities in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Service logic vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause WLAN DoS. plural Huawei Smartphone products have unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202112-0263 CVE-2021-37084 Huawei  Input validation vulnerability in smartphone products CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages. Huawei A vulnerability related to input validation exists in smartphone products.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. This vulnerability stems from the failure of the network system or product to properly verify the input data
VAR-202112-0258 CVE-2021-37014 Huawei  Integer overflow vulnerability in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to device cannot be used properly. Huawei Smartphone products contain an integer overflow vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202112-0225 CVE-2021-37095 Huawei  Integer overflow vulnerability in smartphones CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution. Huawei Smartphones contain an integer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a component of the product that fails to effectively verify integer data
VAR-202112-0350 CVE-2021-37050 plural  Huawei  Vulnerability related to lack of encryption of important data in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality
VAR-202112-0285 CVE-2021-37040 plural  Huawei  Argument insertion or modification vulnerability in smartphone products CVSS V2: 6.8
CVSS V3: 9.8
Severity: CRITICAL
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting. plural Huawei Smartphone products contain an argument injection or modification vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS. No detailed vulnerability details were provided at this time
VAR-202112-0259 CVE-2021-37011 Huawei  Out-of-bounds write vulnerability in smartphone products CVSS V2: 9.4
CVSS V3: 9.1
Severity: CRITICAL
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read. Huawei Smartphone products contain an out-of-bounds write vulnerability.Information is obtained and service operation is interrupted (DoS) It may be in a state
VAR-202112-0234 CVE-2021-37082 Huawei  Race Condition Vulnerability in Smartphones CVSS V2: 4.3
CVSS V3: 5.9
Severity: MEDIUM
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash. Huawei Smartphones contain a race condition vulnerability.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
VAR-202112-0262 CVE-2021-37085 Huawei  Race Condition Vulnerability in Smartphone Products CVSS V2: 7.1
CVSS V3: 5.9
Severity: MEDIUM
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service. Huawei A race condition vulnerability exists in smartphone products.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
VAR-202112-0351 CVE-2021-37049 plural  Huawei  Out-of-bounds write vulnerability in smartphone products CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects. plural Huawei Smartphone products contain an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202112-0391 CVE-2021-37061 Huawei  Resource Exhaustion Vulnerability in Smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Uncontrolled Resource Consumption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Screen projection application denial of service. Huawei Smartphones have a resource exhaustion vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202112-0226 CVE-2021-37094 Huawei  Input validation vulnerability in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service. Huawei Smartphones contain a vulnerability related to input validation.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. The vulnerability is caused by a component of the product not validly validating the data
VAR-202112-0240 CVE-2021-37077 Huawei  in smartphone  NULL  Pointer dereference vulnerability CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
There is a NULL Pointer Dereference vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel crash
VAR-202112-0354 CVE-2021-37039 plural  Huawei  Input validation vulnerability in smartphone products CVSS V2: 3.3
CVSS V3: 6.5
Severity: MEDIUM
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. No detailed vulnerability details were provided at this time
VAR-202112-0224 CVE-2021-37096 HarmonyOS  Input verification vulnerability in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There are security vulnerabilities in Huawei HarmonyOS, which can be exploited by attackers to leak user privacy
VAR-202112-0257 CVE-2021-37048 Huawei  Input validation vulnerability in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to fake visitors to control PC,play a video,etc. Huawei Smartphones contain a vulnerability related to input validation.Information may be tampered with