LiveActive security incident?Get immediate response
CVE archive

August 2021

Browse CVE records published in August 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2047 matching CVEs · Page 35 of 41.

Unknown · CVSS Not scored

CVE-2021-22676: UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an a...

UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).

Published Aug 10, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22517: A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector.

A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulnerability affects versions 10.10, 10.20, 10.30, 10.40, 10.50, 10.60, 10.70, 10.80, 10.0 and 10.91. A privileged user may potentially misuse this feature and thus allow unintended and unauthorized access of data.

Published Aug 5, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22398: There is a logic error vulnerability in several smartphones.

There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations. Affected product versions include: Hulk-AL00C 9.1.1.201(C00E201R8P1);Jennifer-AN00C 10.1.1.171(C00E170R6P3);Jenny-AL10B 10.1.0.228(C00E220R5P1) and OxfordPL-AN10B 10.1.0.116(C00E110R2P1).

Published Aug 2, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22449: There is a logic vulnerability in Elf-G10HN 1.0.0.608.

There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.

Published Aug 23, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22396: There is a privilege escalation vulnerability in some Huawei products.

There is a privilege escalation vulnerability in some Huawei products. Due to improper privilege management, a local attacker with common privilege may access some specific files in the affected products. Successful exploit will cause privilege escalation.Affected product versions include:eCNS280_TD V100R005C00,V100R005C10;eSE620X vESS V100R001C10SPC200,V100R001C20SPC200.

Published Aug 2, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22397: There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0.

There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service.

Published Aug 2, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22400: Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter val...

Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The app can modify specific parameters, causing the system to crash. Affected product include:OxfordS-AN00A 10.0.1.10(C00E10R1P1),10.0.1.105(C00E103R3P3),10.0.1.115(C00E110R3P3),10.0.1.123(C00E121R3P3),10.0.1.135(C00E130R3P3),10.0.1.135(C00E130R4P1),10.0.1.152(C00E140R4P1),10.0.1.160(C00E160R4P1),10.0.1.167(C00E166R4P1),10.0.1.173(C00E172R5P1),10.0.1.178(C00E175R5P1) and 10.1.0.202(C00E79R5P1).

Published Aug 3, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22357: There is a denial of service vulnerability in Huawei products.

There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due to validating inputs insufficiently. Attackers can exploit this vulnerability by sending specific messages to affected module. This can cause denial of service. Affected product versions include: S12700 V200R013C00SPC500, V200R019C00SPC500; S5700 V200R013C00SPC500, V200R019C00SPC500; S6700 V200R013C00SPC500, V200R019C00SPC500; S7700 V200R013C00SPC500, V200R019C00SPC500.

Published Aug 23, 2021 · Updated Aug 3, 2024

Unknown · CVSS Not scored

CVE-2021-22328: There is a denial of service vulnerability in some huawei products.

There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft the specific packet. Successful exploit may cause some services abnormal. Affected product versions include:CloudEngine 12800 V200R005C00SPC800, CloudEngine 5800 V200R005C00SPC800, CloudEngine 6800 V200R005C00SPC800, CloudEngine 7800 V200R005C00SPC800.

Published Aug 23, 2021 · Updated Aug 3, 2024

High · CVSS 8.3

CVE-2021-22289: RCE through Project Upload from Target

Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow an unauthenticated network attacker to execute code.

Published Aug 11, 2022 · Updated Aug 3, 2024