CVE-2021-37127

moderate-risk
Published 2021-10-27

There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.

Do I need to act?

-
0.10% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10 High
NETWORK / LOW complexity

Affected Products (16)

Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware

Affected Vendors

44
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 0/34 · Minimal
Exposure 18/34 · Moderate