CVE-2021-40043
Last modified
CVE-2021-40043 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering of this vulnerability could execute voice commands on the device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ais-Bw80h-00 Firmware | < 9.0.3.4\(h100sp13c00\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-40043?
How severe is CVE-2021-40043?
How do I fix CVE-2021-40043?
Are you affected by CVE-2021-40043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
