Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-37086


There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.


Published

2021-12-07T17:15:09.567

Last Modified

2024-11-21T06:14:37.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.6 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-281

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei harmonyos < 2.0 Yes

References