CVE-2021-37131

There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:huawei:manageone:6.5.1:rc1.b060:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc1.b070:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b020:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b030:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b050:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b060:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b070:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b090:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b010:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b020:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b030:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc100.b050:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc101.b010:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc101.b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b010:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b030:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b050:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b060:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b070:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:-:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:lcn080:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:lcnd81:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:spc100:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.1:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp2001:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp2002:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3001:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3002:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3101:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3102:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc100:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc110:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc120:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc210:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc300:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc310:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00cp2201:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00cp2301:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc100:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc110:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc120:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc190:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc200:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc201:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc202:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc210:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc220:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc221:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc230:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc232:*:*:*:*:*:*:*

History

29 Oct 2021, 01:26

Type Values Removed Values Added
CWE CWE-1236
CPE cpe:2.3:a:huawei:manageone:6.5.1.1:b020:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b070:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc120:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp2001:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc200:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc101.b040:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00cp2201:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc100:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc120:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3101:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b030:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b010:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc202:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc310:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc232:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc1.b060:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc2:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3102:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc101.b010:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b050:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc100:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b030:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc230:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b020:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00cp2301:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc100.b050:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b050:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b040:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc220:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b060:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc110:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3001:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc221:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:lcnd81:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b030:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc110:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:lcn080:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:spc100:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp2002:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:-:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc2.b090:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc201:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b040:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b060:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00cp3002:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc200:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:spc200.b070:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1.1:b010:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:8.0.0:rc3:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc210:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc210:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco:v600r010c00spc300:*:*:*:*:*:*:*
cpe:2.3:h:huawei:imanager_neteco_6000:v600r009c00spc190:*:*:*:*:*:*:*
cpe:2.3:a:huawei:manageone:6.5.1:rc1.b070:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.0
v3 : 6.8
References (MISC) https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211020-01-csv-en - (MISC) https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211020-01-csv-en - Patch, Vendor Advisory

27 Oct 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-27 01:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-37131

Mitre link : CVE-2021-37131

CVE.ORG link : CVE-2021-37131


JSON object : View

Products Affected

huawei

  • imanager_neteco_6000
  • manageone
  • imanager_neteco
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File