CVE-2021-22304

There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:taurus-al00a_firmware:10.0.0.1\(c00e1r1p1\):*:*:*:*:*:*:*
cpe:2.3:h:huawei:taurus-al00a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:49

Type Values Removed Values Added
References () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en - Vendor Advisory () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en - Vendor Advisory

Information

Published : 2021-02-06 03:15

Updated : 2024-11-21 05:49


NVD link : CVE-2021-22304

Mitre link : CVE-2021-22304

CVE.ORG link : CVE-2021-22304


JSON object : View

Products Affected

huawei

  • taurus-al00a_firmware
  • taurus-al00a
CWE
CWE-416

Use After Free