CVE-2021-37035
📋 TL;DR
This vulnerability allows remote attackers to cause a denial of service (DoS) on affected Huawei smartphones by making the targeted app crash unexpectedly. The vulnerability affects Huawei smartphone users who haven't applied security patches. Successful exploitation doesn't require authentication and can be triggered remotely.
💻 Affected Systems
- Huawei smartphones
📦 What is this software?
Emui by Huawei
Magic Ui by Huawei
⚠️ Risk & Real-World Impact
Worst Case
Continuous DoS attacks could render the affected app unusable, potentially disrupting critical functionality if the app provides essential services.
Likely Case
Intermittent app crashes causing user frustration and temporary loss of functionality until the app is restarted.
If Mitigated
With proper patching, no impact as the vulnerability is fully addressed in updated versions.
🎯 Exploit Status
Remote DoS vulnerabilities typically have low exploitation complexity, though specific technical details aren't provided in the references.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Security patch level August 2021 or later
Vendor Advisory: https://consumer.huawei.com/en/support/bulletin/2021/8/
Restart Required: Yes
Instructions:
1. Check for system updates in phone settings
2. Install August 2021 security patch or later
3. Restart device after update installation
🔧 Temporary Workarounds
Disable affected app
allTemporarily disable or uninstall the vulnerable app until patched
Network isolation
allRestrict network access to the device to trusted networks only
🧯 If You Can't Patch
- Isolate device from untrusted networks
- Monitor for abnormal app behavior and crashes
🔍 How to Verify
Check if Vulnerable:
Check security patch level in phone settings (Settings > System & updates > Software update)
Check Version:
Not applicable - check via phone settings interface
Verify Fix Applied:
Confirm security patch level is August 2021 or later
📡 Detection & Monitoring
Log Indicators:
- Unexpected app crashes
- App force close events in system logs
Network Indicators:
- Unusual network traffic patterns to the device
SIEM Query:
Not applicable for consumer devices without centralized logging