Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33658


atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.


Published

2022-03-11T18:15:21.320

Last Modified

2025-04-02T18:33:53.340

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application huawei atune ≤ 0.8 Yes
Operating System openatom openeuler 20.03 No
Operating System openatom openeuler 20.03 No
Operating System openatom openeuler 20.03 No

References