CVE-2021-22420
HIGHCVSS 7.8/10EPSS 0.18%
Last modified
CVE-2021-22420 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing... EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Harmonyos | 2.0 |
References
- https://device.harmonyos.com/cn/docs/security/update/oem_security_update_phone_202106-0000001165452077Not Applicable, Vendor Advisory
- https://device.harmonyos.com/cn/docs/security/update/oem_security_update_phone_202106-0000001165452077Not Applicable, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22420?
A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust of the application trustlist mechanism is missing..
How severe is CVE-2021-22420?
CVE-2021-22420 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.18% probability of exploitation in the next 30 days.
How do I fix CVE-2021-22420?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22415There is an Incorrect Calculation of Buffer Size Vulnerabili…7.5
- CVE-2021-22416A component of the HarmonyOS has a Data Processing Errors vu…7.8
- CVE-2021-22417A component of the HarmonyOS has a Data Processing Errors vu…5.5
- CVE-2021-22418A component of the HarmonyOS has a Integer Overflow or Wrapa…7.8
- CVE-2021-22419A component of the HarmonyOS has a Insufficient Verification…5.5
- CVE-2021-2242Vulnerability in the Oracle Outside In Technology product of…8.2
- CVE-2021-22421A component of the HarmonyOS has a Improper Privilege Manage…7.8
- CVE-2021-22422A component of the HarmonyOS has a Integer Overflow or Wrapa…7.8
- CVE-2021-22423A component of the HarmonyOS has a Out-of-bounds Write Vulne…7.8
- CVE-2021-22424A component of the HarmonyOS has a Kernel Memory Leakage Vul…5.5
- CVE-2021-22425A component of the HarmonyOS has a Double Free vulnerability…7.8
- CVE-2021-22426There is a memory address out of bounds in smartphones. Succ…9.8
Are you affected by CVE-2021-22420?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
