Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-21723


Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a remote attacker can trigger the vulnerability by performing a series of operations, resulting in memory leak, which may eventually lead to device denial of service. This affects: ZXR10 9904, ZXR10 9908, ZXR10 9916, ZXR10 9904-S, ZXR10 9908-S; all versions up to V1.01.10.B12.


Published

2021-01-26T18:16:18.803

Last Modified

2024-11-21T05:48:52.983

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-401

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zte zxr10_9904_firmware ≤ v1.01.10.b12 Yes
Hardware zte zxr10_9904 - No
Operating System zte zxr10_9908_firmware ≤ v1.01.10.b12 Yes
Hardware zte zxr10_9908 - No
Operating System zte zxr10_9916_firmware ≤ v1.01.10.b12 Yes
Hardware zte zxr10_9916 - No
Operating System zte zxr10_9904-s_firmware ≤ v1.01.10.b12 Yes
Hardware zte zxr10_9904-s - No
Operating System zte zxr10_9908-s_firmware ≤ v1.01.10.b12 Yes
Hardware zte zxr10_9908-s - No

References