CVE-2021-22296
Status: ModifiedMedium (5.5)—
A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Base score: 5.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.21%
- Percentile among all scored CVEs: 10
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-noinfo
References
- https://device.harmonyos.com/cn/console/safetyDetail?id=9145efa5d9064d94a7fc3968b6054d83&pageSize=10&pageIndex=1
- https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2021/2021-03.md
- https://www.tenable.com/cve/CVE-2021-22296
- https://device.harmonyos.com/cn/console/safetyDetail?id=9145efa5d9064d94a7fc3968b6054d83&pageSize=10&pageIndex=1
- https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2021/2021-03.md
- https://www.tenable.com/cve/CVE-2021-22296
Raw JSON (NVD)
Show
{
"id": "CVE-2021-22296",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "HarmonyOS",
"versions": [
{
"status": "affected",
"version": "HarmonyOS 2.0"
}
]
}
]
}
],
"published": "2021-03-02T19:15:13.207",
"references": [
{
"url": "https://device.harmonyos.com/cn/console/safetyDetail?id=9145efa5d9064d94a7fc3968b6054d83&pageSize=10&pageIndex=1",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2021/2021-03.md",
"tags": [
"Third Party Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.tenable.com/cve/CVE-2021-22296",
"tags": [
"Third Party Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://device.harmonyos.com/cn/console/safetyDetail?id=9145efa5d9064d94a7fc3968b6054d83&pageSize=10&pageIndex=1",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2021/2021-03.md",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.tenable.com/cve/CVE-2021-22296",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system."
},
{
"lang": "es",
"value": "Un componente de HarmonyOS versión 2.0, presenta una vulnerabilidad de DoS. Los atacantes locales pueden explotar esta vulnerabilidad para montar un sistema de archivos en el dispositivo objetivo, provocando una DoS del sistema de archivos"
}
],
"lastModified": "2026-06-17T03:36:57.370",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:harmonyos:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AD62E8B-CB4B-43A6-98E8-09A8A1A3505B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@huawei.com"
}