VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202112-0354 CVE-2021-37039 plural  Huawei  Input validation vulnerability in smartphone products CVSS V2: 3.3
CVSS V3: 6.5
Severity: MEDIUM
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. No detailed vulnerability details were provided at this time
VAR-202112-0247 CVE-2021-37067 Huawei  Information disclosure vulnerability in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality impacted. Huawei Smartphones are vulnerable to information disclosure.Information may be obtained
VAR-202112-0343 CVE-2021-37092 plural  Huawei  Incomplete Cleanup Vulnerability in Smartphone Products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected. plural Huawei An incomplete cleanup vulnerability exists in smartphone products.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. HUAWEI HarmonyOS has a resource management error vulnerability. This vulnerability is caused by a resource not closing or releasing vulnerability in a certain component of HarmonyOS. No detailed vulnerability details were provided at this time
VAR-202112-0353 CVE-2021-37044 plural  Huawei  Vulnerability related to improper retention of permissions in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. plural Huawei A vulnerability related to improper retention of permissions exists in smartphone products.Service operation interruption (DoS) It may be in a state
VAR-202112-0344 CVE-2021-37074 plural  Huawei  Race Condition Vulnerability in Smartphone Products CVSS V2: 9.3
CVSS V3: 8.1
Severity: HIGH
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation. plural Huawei A race condition vulnerability exists in smartphone products.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202112-0342 CVE-2021-37093 plural  Huawei  Vulnerabilities in smartphone products CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers steal short messages. plural Huawei Smartphone products have unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. The vulnerability is caused by a component of the product that does not effectively authenticate user identities. No detailed vulnerability details were provided at this time
VAR-202112-0327 CVE-2021-37075 plural  Huawei  Vulnerabilities in smartphone products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected. plural Huawei Smartphone products have unspecified vulnerabilities.Information may be obtained
VAR-202112-0223 CVE-2021-37099 HarmonyOS  Past traversal vulnerability in CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file. HarmonyOS Exists in a past traversal vulnerability.Information is tampered with and service operation is interrupted (DoS) It may be in a state. Huawei HarmonyOS is China's Huawei ( Huawei ) company's operating system. Provide a microkernel-based full-scenario distributed operating system
VAR-202112-0352 CVE-2021-37045 plural  Huawei  Vulnerability related to use of freed memory in smartphone products CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed. plural Huawei A vulnerability related to use of freed memory exists in smartphone products.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202112-0231 CVE-2021-37087 Huawei  Path Traversal Vulnerability in Smartphones CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file. Huawei Smartphones have a path traversal vulnerability.Information may be obtained and information may be tampered with
VAR-202112-0225 CVE-2021-37095 Huawei  Integer overflow vulnerability in smartphones CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution. Huawei Smartphones contain an integer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a component of the product that fails to effectively verify integer data
VAR-202112-0226 CVE-2021-37094 Huawei  Input validation vulnerability in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system denial of service. Huawei Smartphones contain a vulnerability related to input validation.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. The vulnerability is caused by a component of the product not validly validating the data
VAR-202112-0224 CVE-2021-37096 HarmonyOS  Input verification vulnerability in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to user privacy disclosed. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There are security vulnerabilities in Huawei HarmonyOS, which can be exploited by attackers to leak user privacy
VAR-202112-0222 CVE-2021-37100 Huawei  Authentication Vulnerability in Smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Improper Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to account authentication bypassed. Huawei Smartphones have an authentication vulnerability.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a component of the product that does not effectively authenticate user identities
VAR-202112-0346 CVE-2021-37054 plural  Huawei  Authentication Vulnerability in Smartphone Products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. plural Huawei Smartphone products contain an authentication vulnerability.Information may be obtained
VAR-202112-0333 CVE-2021-37043 plural  Huawei  Authentication Vulnerability in Smartphone Products CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious application processes occupy system resources. plural Huawei Smartphone products contain an authentication vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202112-0244 CVE-2021-37071 Huawei  Vulnerabilities in smartphones CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
There is a Business Logic Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to persistent dos. Huawei Smartphones have unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202109-1958 CVE-2021-22480 HarmonyOS  Integer overflow vulnerability in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow. HarmonyOS Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202112-0285 CVE-2021-37040 plural  Huawei  Argument insertion or modification vulnerability in smartphone products CVSS V2: 6.8
CVSS V3: 9.8
Severity: CRITICAL
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting. plural Huawei Smartphone products contain an argument injection or modification vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS. No detailed vulnerability details were provided at this time
VAR-202112-0229 CVE-2021-37089 Huawei  Incomplete Cleanup Vulnerability in Smartphone Products CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to kernel restart. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system