PT-2021-14966 · Huawei · Cloudengine 7800+4
Published
2021-04-07
·
Updated
2021-05-08
·
CVE-2021-22332
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
CloudEngine 5800 (affected versions not specified)
CloudEngine 6800 (affected versions not specified)
CloudEngine 7800 (affected versions not specified)
CloudEngine 12800 (affected versions not specified)
Description:
The issue is related to a pointer double free vulnerability. When a function is called, the same memory pointer is copied to two functional modules. Attackers can exploit this vulnerability by performing a malicious operation to cause the pointer double free, potentially leading to module crash and compromising normal service.
Recommendations:
For CloudEngine 5800, update to a version that fixes the pointer double free vulnerability.
For CloudEngine 6800, update to a version that fixes the pointer double free vulnerability.
For CloudEngine 7800, update to a version that fixes the pointer double free vulnerability.
For CloudEngine 12800, update to a version that fixes the pointer double free vulnerability.
As a temporary workaround, consider restricting access to the functional modules that use the copied memory pointer to minimize the risk of exploitation.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudengine 12800
Cloudengine 5800
Cloudengine 6800
Cloudengine 7800
Huawei Vrp