CVE-2021-40046
Description
PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
PCManager versions 11.1.1.95 has a privilege escalation vulnerability allowing unauthorized access to resources.
Vulnerability
PCManager version 11.1.1.95 contains a privilege escalation vulnerability (Vulnerability ID: HWPSIRT-2021-49498) that allows an attacker to access resources beyond their granted privileges. The vulnerability requires the attacker to send a crafted message to the system [1]. The affected product is Huawei PCManager versions 11.1.1.95, with the resolved version being 12.0.1.20 (SP1) [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted message to the system [1]. The attack does not require authentication but relies on the ability to deliver the crafted input to the PCManager service. The exact message structure and delivery method are not detailed in the references.
Impact
Successful exploitation allows the attacker to access certain resources that are beyond their normal privilege level [1]. This could lead to unauthorized information disclosure or unauthorized modification of system resources, depending on the nature of the protected resource. The vulnerability is classified as a privilege escalation issue [1].
Mitigation
Huawei has released a software update to fix this vulnerability. The resolved version for PCManager is 12.0.1.20 (SP1) [1]. Users should update to this version or later to mitigate the risk. No workarounds have been provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the advisory date [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- PCManager/PCManagerdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20220216-01-priesc-enmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.