Vulnerabilities > Huawei > Hisuite > 2.3.28

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-9100 Untrusted Search Path vulnerability in Huawei Hisuite
Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability.
local
huawei CWE-426
4.4
2019-06-13 CVE-2019-5245 Untrusted Search Path vulnerability in Huawei Hisuite
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability.
local
low complexity
huawei CWE-426
4.6
2016-07-13 CVE-2016-5821 Permissions, Privileges, and Access Controls vulnerability in Huawei Hisuite
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
local
low complexity
huawei CWE-264
7.2
2016-06-30 CVE-2016-4086 Security Bypass vulnerability in Huawei HiSuite
Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.
2.9