CVE-2021-22397

MEDIUM

Huawei ManageOne 8.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service.

References (1)

Core 1

Scores

CVSS v3 6.7
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
huawei/manageone 8.0.0
Published Aug 02, 2021
Tracked Since Feb 18, 2026