CVE-2021-37000

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 28, 2024
Updated: Mar 18, 2025
CWE ID 276
CWE ID 255

Summary

CVE-2021-37000 is a new vulnerability affecting certain Huawei wearable devices. The issue lies in the permission management system, which allows unauthorized access to sensitive data or functionalities. An attacker can exploit this weakness to gain elevated privileges, potentially leading to data theft or device manipulation. Users are advised to update their devices as soon as patches are available to mitigate this risk. Huawei has acknowledged the issue and is working on a fix.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HarmonyOS

Affected Vendors

  • Huawei Technologies