SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22340

There is a multiple threads race condition vulnerability in Huawei product.

MEDIUM 4.1EPSS 0.11%

Does this matter?

Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.

Description

There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause the system to crash. Affected product versions include: ManageOne 6.5.1.SPC200, 8.0.0,8.0.0-LCND81, 8.0.0.SPC100, 8.0.1,8.0.RC2, 8.0.RC3, 8.0.RC3.SPC100;SMC2.0 V600R019C10SPC700,V600R019C10SPC702, V600R019C10SPC703,V600R019C10SPC800, V600R019C10SPC900, V600R019C10SPC910, V600R019C10SPC920, V600R019C10SPC921, V600R019C10SPC922, V600R019C10SPC930, V600R019C10SPC931

CVSS 3.1
4.1 MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS
0.11% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-362
Affected
huawei/manageone · huawei/smc2.0
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.