CVE-2021-22440 Details
Description
There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow the attacker to access a location that is outside of the restricted directory by a crafted filename. Affected product versions include:HUAWEI Mate 20 9.0.0.195(C01E195R2P1), 9.1.0.139(C00E133R3P1);HUAWEI Mate 20 Pro 9.0.0.187(C432E10R1P16), 9.0.0.188(C185E10R2P1), 9.0.0.245(C10E10R2P1), 9.0.0.266(C432E10R1P16), 9.0.0.267(C636E10R2P1), 9.0.0.268(C635E12R1P16), 9.0.0.278(C185E10R2P1); Hima-L29C 9.0.0.105(C10E9R1P16), 9.0.0.105(C185E9R1P16), 9.0.0.105(C636E9R1P16); Laya-AL00EP 9.1.0.139(C786E133R3P1); OxfordS-AN00A 10.1.0.223(C00E210R5P1); Tony-AL00B 9.1.0.257(C00E222R2P1).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210630-01-pathtraversal-en | CVE | Vendor Advisory |
| https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210630-01-pathtraversal-en | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| huawei mate 20 firmware | 9.0.0.195(c01e195r2p1) 9.1.0.139(c00e133r3p1) |
CPE
Remediation
| |
| huawei mate 20 | All versions |
CPE
Remediation
| |
| huawei mate 20 pro firmware | 9.0.0.187(c432e10r1p16) 9.0.0.188(c185e10r2p1) 9.0.0.245(c10e10r2p1) 9.0.0.266(c432e10r1p16) 9.0.0.267(c636e10r2p1) 9.0.0.268(c635e12r1p16) 9.0.0.278(c185e10r2p1) |
CPE
Remediation
| |
| huawei mate 20 pro | All versions |
CPE
Remediation
| |
| huawei hima-l29c firmware | 9.0.0.105(c10e9r1p16) 9.0.0.105(c185e9r1p16) 9.0.0.105(c636e9r1p16) |
CPE
Remediation
| |
| huawei hima-l29c | All versions |
CPE
Remediation
| |
| huawei laya-al00ep firmware | 9.1.0.139(c786e133r3p1) |
CPE
Remediation
| |
| huawei laya-al00ep | All versions |
CPE
Remediation
| |
| huawei oxfords-an00a firmware | 10.1.0.223(c00e210r5p1) |
CPE
Remediation
| |
| huawei oxfords-an00a | All versions |
CPE
Remediation
| |
| huawei tony-al00b firmware | 9.1.0.257(c00e222r2p1) |
CPE
Remediation
| |
| huawei tony-al00b | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 15, 2021 | Initial Analysis | [email protected] |