Vulnerability Details CVE-2021-33658
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.8%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2021-33658
-
cpe:2.3:a:huawei:atune:0.3
-
cpe:2.3:a:huawei:atune:0.8
-
cpe:2.3:o:openatom:openeuler:20.03