Vulnerabilities > Huawei > Hisuite > 2.3.55

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-9100 Uncontrolled Search Path Element vulnerability in Huawei Hisuite
Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability.
local
low complexity
huawei CWE-427
7.8
2019-06-13 CVE-2019-5245 Uncontrolled Search Path Element vulnerability in Huawei Hisuite
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability.
local
low complexity
huawei CWE-427
5.3
2016-07-13 CVE-2016-5821 Permissions, Privileges, and Access Controls vulnerability in Huawei Hisuite
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
local
low complexity
huawei CWE-264
7.8
2016-06-30 CVE-2016-4086 Unspecified vulnerability in Huawei Hisuite
Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.
high complexity
huawei
5.3