CVE-2021-37101

MEDIUM

AIS-BW50-00 9.0.6.2(H100SP10C00/H100SP15C00) - Privilege Escalation

Title source: llm
STIX 2.1

Description

There is an improper authorization vulnerability in AIS-BW50-00 9.0.6.2(H100SP10C00) and 9.0.6.2(H100SP15C00). Due to improper authorization mangement, an attakcer can exploit this vulnerability by physical accessing the device and implant malicious code. Successfully exploit could leads to arbitrary code execution in the target device.

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
huawei/ais-bw50-00_firmware 9.0.6.2\(h100sp10c00\)
huawei/ais-bw50-00_firmware 9.0.6.2\(h100sp15c00\)
Published Sep 09, 2021
Tracked Since Feb 18, 2026