CVE-2021-39976
Last modified
CVE-2021-39976 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Cloudengine 5800 Firmware | v200r020c00spc600 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-39976?
How severe is CVE-2021-39976?
How do I fix CVE-2021-39976?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-39970HwPCAssistant has a Improper Input Validation vulnerability.…7.5
- CVE-2021-39971Password vault has a External Control of System or Configura…7.5
- CVE-2021-39972MyHuawei-App has a Exposure of Sensitive Information to an U…7.5
- CVE-2021-39973There is a Null pointer dereference in Smartphones.Successfu…7.5
- CVE-2021-39974There is an Out-of-bounds read in Smartphones.Successful exp…7.5
- CVE-2021-39975Hilinksvc has a Data Processing Errors vulnerability.Success…7.5
- CVE-2021-39977The HwNearbyMain module has a NULL Pointer Dereference vulne…7.5
- CVE-2021-39978Telephony application has a SQL Injection vulnerability.Succ…7.5
- CVE-2021-39979HHEE system has a Code Injection vulnerability.Successful ex…9.8
- CVE-2021-3998A flaw was found in glibc. The realpath() function can mista…7.5
- CVE-2021-39980Telephony application has a Exposure of Sensitive Informatio…5.3
- CVE-2021-39981Chang Lian application has a vulnerability which can be mali…5.3
Are you affected by CVE-2021-39976?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
