LiveActive security incident?Get immediate response
CVE Record

CVE-2021-22322: There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone.

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This is a Huawei smartphone software vulnerability where a critical function lacks proper authentication. If exploited, it could reduce data confidentiality on affected devices. The public record names EMUI 11.0.0 and Magic UI 4.0.0, but does not provide device models, attack prerequisites, CVSS scoring, or confirmed exploitation.

Executive priority

Set priority after asset discovery. If affected Huawei phones handle corporate email, files, or privileged applications, treat remediation as business-relevant because the stated impact is confidentiality loss. Sparse public detail means uncertainty should drive verification, not dismissal.

Technical view

CVE-2021-22322 is described as Missing Authentication for Critical Function in Huawei Smartphone software. The affected software listed is EMUI 11.0.0 and Magic UI 4.0.0. Available sources state successful exploitation may impair data confidentiality, but do not describe the vulnerable component, required access, or remediation details.

Likely exposure

Exposure is most likely limited to Huawei smartphones running EMUI 11.0.0 or Magic UI 4.0.0. The source bundle does not identify specific phone models, regions, configurations, or whether managed enterprise devices are affected.

Exploitation context

CISA KEV status is false, and the supplied sources do not cite active exploitation, public exploit availability, or attacker use. Treat exploitation status as unconfirmed, not absent.

Researcher notes

Public data is thin: no CVSS vector, CWE entry, model list, affected component, prerequisites, or patch mapping is included in the bundle. Avoid assuming remote exploitability or specific fixes. The key research task is correlating Huawei bulletin details with actual fleet models and firmware builds.

Mitigation direction

  • Identify Huawei devices running EMUI 11.0.0 or Magic UI 4.0.0.
  • Review Huawei's March 2021 security bulletin for vendor guidance.
  • Apply Huawei-supported security updates through official device management channels.
  • Prioritize business-managed devices that store or access sensitive data.
  • Restrict sensitive access from unpatched affected devices where feasible.

Validation and detection

  • Inventory Huawei smartphone OS versions in MDM or endpoint records.
  • Confirm whether any device reports EMUI 11.0.0 or Magic UI 4.0.0.
  • Check Huawei security bulletin status for each affected device model.
  • Verify devices have received applicable vendor security updates.
  • Document unresolved devices and compensating access controls.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-22322 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aEMUI;Magic UIEMUI 11.0.0, Magic UI 4.0.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.