Vulnerability Description
There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Harmonyos | < 2.0 |
| Huawei | Emui | 10.0.0 |
| Huawei | Magic Ui | 3.0.0 |
Related Weaknesses (CWE)
References
- https://consumer.huawei.com/en/support/bulletin/2022/1/Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-202201-0Vendor Advisory
- https://consumer.huawei.com/en/support/bulletin/2022/1/Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-202201-0Vendor Advisory
FAQ
What is CVE-2021-40037?
CVE-2021-40037 is a vulnerability with a CVSS score of 5.5 (MEDIUM). There is a Vulnerability of accessing resources using an incompatible type (type confusion) in the MPTCP subsystem in smartphones. Successful exploitation of this vulnerability may cause the system to...
How severe is CVE-2021-40037?
CVE-2021-40037 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40037?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Harmonyos, Huawei Emui, Huawei Magic Ui.