Vulnerabilities > Huawei > Hisuite > High

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-9100 Uncontrolled Search Path Element vulnerability in Huawei Hisuite
Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability.
local
low complexity
huawei CWE-427
7.8
2017-04-02 CVE-2016-8274 Improper Access Control vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can make the system load malicious DLL files to execute arbitrary code.
local
low complexity
huawei CWE-284
7.8
2017-04-02 CVE-2016-8273 Improper Access Control vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the software package before installing; an attacker can launch an MITM attack to interrupt or replace the downloaded software package and further compromise the PC.
local
low complexity
huawei CWE-284
7.8
2016-07-13 CVE-2016-5821 Permissions, Privileges, and Access Controls vulnerability in Huawei Hisuite
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.
local
low complexity
huawei CWE-264
7.8