Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2018-07-05 CVE-2018-7944 Unspecified vulnerability in Huawei Emily-Al00A Firmware 8.1.0.106(Sp2C00)/8.1.0.107(Sp5C00)
Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (FRP) bypass vulnerability.
low complexity
huawei
6.8
2018-07-02 CVE-2017-17317 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
Common Open Policy Service Protocol (COPS) module in Huawei USG6300 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace USG6500 V100R001C10; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; Secospace USG6600 V100R001C00; V100R001C20; V100R001C30; V500R001C00; V500R001C20; V500R001C30; V500R001C50; TE30 V100R001C02; V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C01; V100R001C10; V500R002C00; V600R006C00 has a buffer overflow vulnerability.
network
high complexity
huawei CWE-119
3.7
2018-07-02 CVE-2017-17316 Out-of-bounds Read vulnerability in Huawei products
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
5.3
2018-07-02 CVE-2017-17175 Improper Input Validation vulnerability in Huawei Mate 9 PRO Lonal00B8.0.0.334(C00)/Lonal00B8.0.0.340A(C00)/Lonal00B8.0.0.343(C00)
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability.
low complexity
huawei CWE-20
6.5
2018-06-14 CVE-2017-17309 Path Traversal vulnerability in Huawei Hg255S-10 Firmware V100R001C163B025Sp02
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
network
low complexity
huawei CWE-22
7.5
2018-06-14 CVE-2017-17173 Improper Input Validation vulnerability in Huawei Mate 9 PRO Fimware Lonal00B8.0.0.334(C00)/Lonal00B8.0.0.340A(C00)
Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability.
local
low complexity
huawei CWE-20
7.8
2018-06-14 CVE-2017-17172 Improper Handling of Exceptional Conditions vulnerability in Huawei Lyo-L21
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability.
local
low complexity
huawei CWE-755
7.3
2018-06-05 CVE-2018-7943 Improper Authentication vulnerability in Huawei products
There is an authentication bypass vulnerability in some Huawei servers.
network
low complexity
huawei CWE-287
8.8
2018-06-01 CVE-2018-7976 Cross-site Scripting vulnerability in Huawei Espace Desktop 300R001C00/300R001C50
There is a stored cross-site scripting (XSS) vulnerability in Huawei eSpace Desktop V300R001C00 and V300R001C50 version.
network
low complexity
huawei CWE-79
5.4
2018-06-01 CVE-2018-7951 Code Injection vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-94
8.8