Input Validation Flaw in Huawei Smartphones
CVE-2021-22400

5.5MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
3 August 2021

Summary

Huawei smartphones are susceptible to an input validation vulnerability due to inadequate parameter checks. This weakness permits an attacker to deceive users into installing malicious applications. Once installed, these apps can alter critical system parameters, potentially causing significant disruptions such as system crashes. Users of affected models should remain vigilant and update their devices to mitigate the risks associated with this vulnerability. For more details, refer to Huawei's security advisory.

Affected Version(s)

OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1),10.1.0.202(C00E79R5P1)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.