Vulnerabilities > Huawei > Oceanstor UDS Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-03-13 CVE-2015-2254 Information Exposure vulnerability in Huawei Oceanstor UDS Firmware
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to capture and change patch loading information resulting in the deletion of directory files and compromise of system functions when loading a patch.
network
low complexity
huawei CWE-200
critical
9.1
2017-06-08 CVE-2015-2253 Information Exposure vulnerability in Huawei Oceanstor UDS Firmware V100R002C01Spc101
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
local
low complexity
huawei CWE-200
5.0
2017-06-08 CVE-2015-2252 Code Injection vulnerability in Huawei Oceanstor UDS Firmware V100R002C01Spc101
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.
network
low complexity
huawei CWE-94
8.8
2017-06-08 CVE-2015-2251 Information Exposure vulnerability in Huawei Oceanstor UDS Firmware V100R002C01Spc101
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.
network
low complexity
huawei CWE-200
7.5