Vulnerability Description
There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Elf-G10Hn | 1.0.0.608 |
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210630-01-logic-Vendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210630-01-logic-Vendor Advisory
FAQ
What is CVE-2021-22449?
CVE-2021-22449 is a vulnerability with a CVSS score of 7.5 (HIGH). There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful expl...
How severe is CVE-2021-22449?
CVE-2021-22449 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22449?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Elf-G10Hn.