CVE-2021-37127
moderate-risk
Published 2021-10-27
There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file. Affected product versions include:iManager NetEco V600R010C00CP2001,V600R010C00CP2002,V600R010C00SPC100,V600R010C00SPC110,V600R010C00SPC120,V600R010C00SPC200,V600R010C00SPC210,V600R010C00SPC300;iManager NetEco 6000 V600R009C00SPC100,V600R009C00SPC110,V600R009C00SPC120,V600R009C00SPC190,V600R009C00SPC200,V600R009C00SPC201,V600R009C00SPC202,V600R009C00SPC210.
Do I need to act?
-
0.10% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.2/10
High
NETWORK
/ LOW complexity
Affected Products (16)
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco 6000 Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Imanager Neteco Firmware
Affected Vendors
References (2)
44
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
0/34 · Minimal
Exposure
18/34 · Moderate