PT-2021-7551 · Huawei · Huawei Pc Smart Full Scene+1
Published
2021-10-08
·
Updated
2021-10-28
·
CVE-2021-37124
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei PCManager version 11.1.1.97
Huawei PC Smart Full Scene 11.1
Description
The issue is related to a path traversal vulnerability in the Huawei PC product. This vulnerability arises because the product does not properly filter paths with special characters, allowing attackers to construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport a file to a certain path. The vulnerability is associated with incorrect restriction of the directory path name with limited access.
Recommendations
For Huawei PCManager version 11.1.1.97, consider updating to a version that fixes this issue.
For Huawei PC Smart Full Scene 11.1, consider updating to a version that fixes this issue.
As a temporary workaround, consider restricting access to paths that can be modified by the application to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Pc Smart Full Scene
Huawei Pcmanager