Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-22340

Опубликовано: 29 июн. 2021
Источник: nvd
CVSS3: 4.1
CVSS2: 4.7
EPSS Низкий

Описание

There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause the system to crash. Affected product versions include: ManageOne 6.5.1.SPC200, 8.0.0,8.0.0-LCND81, 8.0.0.SPC100, 8.0.1,8.0.RC2, 8.0.RC3, 8.0.RC3.SPC100;SMC2.0 V600R019C10SPC700,V600R019C10SPC702, V600R019C10SPC703,V600R019C10SPC800, V600R019C10SPC900, V600R019C10SPC910, V600R019C10SPC920, V600R019C10SPC921, V600R019C10SPC922, V600R019C10SPC930, V600R019C10SPC931

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:huawei:manageone:6.5.1:spc200:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:-:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:lcnd81:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc3.spc100:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:spc100:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc700:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc702:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc703:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc800:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc900:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc910:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc920:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc921:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc922:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc930:*:*:*:*:*:*:*
cpe:2.3:a:huawei:smc2.0:v600r019c10spc931:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00016
Низкий

4.1 Medium

CVSS3

4.7 Medium

CVSS2

Дефекты

CWE-362

Связанные уязвимости

github
больше 3 лет назад

There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause the system to crash. Affected product versions include: ManageOne 6.5.1.SPC200, 8.0.0,8.0.0-LCND81, 8.0.0.SPC100, 8.0.1,8.0.RC2, 8.0.RC3, 8.0.RC3.SPC100;SMC2.0 V600R019C10SPC700,V600R019C10SPC702, V600R019C10SPC703,V600R019C10SPC800, V600R019C10SPC900, V600R019C10SPC910, V600R019C10SPC920, V600R019C10SPC921, V600R019C10SPC922, V600R019C10SPC930, V600R019C10SPC931

CVSS3: 4.1
fstec
почти 5 лет назад

Уязвимость системы управления центрами обработки данных ManageOne, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 3%
0.00016
Низкий

4.1 Medium

CVSS3

4.7 Medium

CVSS2

Дефекты

CWE-362