Vulnerability Description
There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport a file to certain path.Affected product versions include:PC Smart Full Scene 11.1 versions PCManager 11.1.1.97.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Pc Smart Full Scene | 11.1 |
| Huawei | Pcmanager | 11.1.1.97 |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211008-01-share-Vendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211008-01-share-Vendor Advisory
FAQ
What is CVE-2021-37124?
CVE-2021-37124 is a vulnerability with a CVSS score of 6.5 (MEDIUM). There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit th...
How severe is CVE-2021-37124?
CVE-2021-37124 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37124?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Pc Smart Full Scene, Huawei Pcmanager.