Vulnerability Description
There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ais-Bw50-00 Firmware | 9.0.6.2\(h100sp10c00\) |
| Huawei | Ais-Bw50-00 | - |
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210908-01-badautVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210908-01-badautVendor Advisory
FAQ
What is CVE-2021-37101?
CVE-2021-37101 is a vulnerability with a CVSS score of 6.8 (MEDIUM). There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by ph...
How severe is CVE-2021-37101?
CVE-2021-37101 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37101?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ais-Bw50-00 Firmware, Huawei Ais-Bw50-00.