CVE-2021-40043
Estado: ModificadaAlta (7.8)—
The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering of this vulnerability could execute voice commands on the device.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-40043",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "AIS-BW80H-00",
"versions": [
{
"status": "affected",
"version": "versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00)"
}
]
}
]
}
],
"published": "2022-02-25T19:15:12.397",
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220126-01-df75863e-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220126-01-df75863e-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering of this vulnerability could execute voice commands on the device."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de inyección de comandos láser en las versiones de AIS-BW80H-00 anteriores a AIS-BW80H-00 9.0.3.4(H100SP13C00). Los dispositivos no pueden defenderse eficazmente contra las interferencias maliciosas externas. Los atacantes necesitan que el dispositivo sea visualmente explotable y un desencadenado exitoso de esta vulnerabilidad podría ejecutar comandos de voz en el dispositivo.\n"
}
],
"lastModified": "2026-06-17T04:06:26.747",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:ais-bw80h-00_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A69A34B8-C1F7-4EC7-9D4A-FACE4B6A8DD9",
"versionEndExcluding": "9.0.3.4\\(h100sp13c00\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:ais-bw80h-00:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "11FA0E49-5801-44FD-86F9-425FC1431BC5"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}