Vulnerabilities > Huawei > Hisuite > 4.0.5.300.ove

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-9100 Untrusted Search Path vulnerability in Huawei Hisuite
Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability.
local
huawei CWE-426
4.4
2019-06-13 CVE-2019-5245 Untrusted Search Path vulnerability in Huawei Hisuite
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability.
local
low complexity
huawei CWE-426
4.6
2017-04-02 CVE-2016-8274 Improper Access Control vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can make the system load malicious DLL files to execute arbitrary code.
local
low complexity
huawei CWE-284
7.2
2017-04-02 CVE-2016-8273 Improper Input Validation vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
local
huawei CWE-20
6.9
2017-04-02 CVE-2016-8272 Information Exposure vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the system can copy out the user's proxy password, causing information leaks.
local
low complexity
huawei CWE-200
2.1