HIGH · 7.5

CVE-2021-37129

There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cau...

Vulnerability Description

There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005C00;NIP6600 V500R005C00,V500R005C20;S12700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600,V200R013C00SPC500,V200R019C00SPC200,V200R019C00SPC500,V200R019C10SPC200,V200R020C00,V200R020C10;S1700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S2700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S5700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600,V200R019C00SPC500;S6700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;S7700 V200R010C00SPC600,V200R010C00SPC700,V200R011C10SPC500,V200R011C10SPC600;S9700 V200R010C00SPC600,V200R011C10SPC500,V200R011C10SPC600;USG9500 V500R005C00,V500R005C20.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiIps Module Firmwarev500r005c00
HuaweiIps Module-
HuaweiNgfw Module Firmwarev500r005c00
HuaweiNgfw Module-
HuaweiNip6600 Firmwarev500r005c00
HuaweiNip6600-
HuaweiS12700 Firmwarev200r010c00spc600
HuaweiS12700-
HuaweiS1700 Firmwarev200r010c00spc600
HuaweiS1700-
HuaweiS2700 Firmwarev200r010c00spc600
HuaweiS2700-
HuaweiS5700 Firmwarev200r010c00spc600
HuaweiS5700-
HuaweiS6700 Firmwarev200r010c00spc600
HuaweiS6700-
HuaweiS7700 Firmwarev200r010c00spc600
HuaweiS7700-
HuaweiS9700 Firmwarev200r010c00spc600
HuaweiS9700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-37129?

CVE-2021-37129 is a vulnerability with a CVSS score of 7.5 (HIGH). There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cau...

How severe is CVE-2021-37129?

CVE-2021-37129 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-37129?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ips Module Firmware, Huawei Ips Module, Huawei Ngfw Module Firmware, Huawei Ngfw Module, Huawei Nip6600 Firmware.