LiveActive security incident?Get immediate response
CVE Record

CVE-2021-22385: A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability.

A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code Execution.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This vulnerability affects certain Huawei smartphone operating system versions and could let a local attacker reach kernel code execution. That is a serious device-compromise impact, but the source bundle does not show remote exploitation, public exploitation, KEV listing, CVSS scoring, or detailed patch mechanics.

Executive priority

Treat this as high priority where Huawei smartphones are used for corporate access, because kernel code execution can undermine endpoint trust. Urgency is lower than a confirmed remote or exploited vulnerability, but exposed devices should be identified and updated through vendor guidance.

Technical view

CVE-2021-22385 is described as external control of a system or configuration setting in a Huawei smartphone component. The listed impact is local attacker exploitation leading to kernel code execution. Affected platforms include EMUI 10.1.0/10.1.1/11.0.0, Magic UI 3.1.0/3.1.1/4.0.0, and HarmonyOS 2.0.

Likely exposure

Exposure is most likely in managed or personally owned Huawei smartphones running the listed EMUI, Magic UI, or HarmonyOS versions. The bundle does not identify specific device models, component names, or CPEs, so asset validation must rely on OS/version inventory and Huawei bulletin guidance.

Exploitation context

The provided CVE text says exploitation requires local attacker access. The bundle marks KEV as false and provides no cited evidence of active exploitation, public exploit availability, or remote attack paths. Kernel code execution increases impact if an attacker already has local execution or access on the device.

Researcher notes

Public details in the bundle are limited: no CVSS vector, CWE, vulnerable component name, model list, exploit chain, or patch diff is provided. Analysis should avoid assumptions beyond local attack requirements, affected OS versions, and kernel code execution impact stated in the CVE record.

Mitigation direction

  • Review Huawei June 2021 security bulletin for affected device guidance.
  • Apply applicable Huawei or HarmonyOS security updates to affected phones.
  • Prioritize corporate-managed Huawei devices running listed OS versions.
  • Restrict untrusted app installation on affected devices until updated.
  • Check vendor guidance if no update path is available.

Validation and detection

  • Inventory Huawei smartphones by OS family and version.
  • Compare devices against listed EMUI, Magic UI, and HarmonyOS versions.
  • Confirm applicable June 2021 security update status or later.
  • Review mobile-device management records for unmanaged Huawei endpoints.
  • Document devices without a confirmed vendor update path.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-22385 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aEMUI;Magic UI;HarmonyOSEMUI 11.0.0,EMUI 10.1.1,EMUI 10.1.0, Magic UI 4.0.0,Magic UI 3.1.1,Magic UI 3.1.0, HarmonyOS 2.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.