CVE-2021-22303

LOW

Huawei Taurus-al00a Firmware - Double Free

Title source: rule

Description

There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free. This may lead to module crash, compromising normal service.

Scores

CVSS v3 3.3
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Classification

CWE
CWE-415
Status published

Affected Products (1)

huawei/taurus-al00a_firmware

Timeline

Published Feb 06, 2021
Tracked Since Feb 18, 2026