Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2018-04-11 CVE-2017-8154 Cleartext Transmission of Sensitive Information vulnerability in Huawei Honor 8 Lite Firmware
The Themes App Honor 8 Lite Huawei mobile phones with software of versions before Prague-L31C576B172, versions before Prague-L31C530B160, versions before Prague-L31C432B180 has a man-in-the-middle (MITM) vulnerability due to the use of the insecure HTTP protocol for theme download.
network
high complexity
huawei CWE-319
5.3
2018-04-11 CVE-2017-17308 Improper Input Validation vulnerability in Huawei products
SCCPX module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 has an invalid memory access vulnerability.
network
low complexity
huawei CWE-20
5.3
2018-04-11 CVE-2017-15327 Information Exposure vulnerability in Huawei S12700 Firmware, S7700 Firmware and S9700 Firmware
S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S7700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S9700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R008C00, V200R009C00, V200R010C00 have an improper authorization vulnerability on Huawei switch products.
network
low complexity
huawei CWE-200
4.3
2018-03-23 CVE-2017-15326 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Huawei Dbs3900 TDD LTE Firmware V100R003C00/V100R004C10
DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability.
network
low complexity
huawei CWE-327
4.3
2018-03-23 CVE-2017-15325 Integer Overflow or Wraparound vulnerability in Huawei products
The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Prague-AL00BC00B211, versions earlier than Prague-AL00CC00B211, versions earlier than Prague-TL00AC01B211, versions earlier than Prague-TL10AC01B211 has integer overflow vulnerability due to the lack of parameter validation.
local
low complexity
huawei CWE-190
7.8
2018-03-20 CVE-2017-8187 Improper Privilege Management vulnerability in Huawei Fusionsphere Openstack Firmware V100R006C00Spc102(Nfv)
Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability.
network
low complexity
huawei CWE-269
7.2
2018-03-20 CVE-2017-8176 Unspecified vulnerability in Huawei Iptv STB Firmware
Huawei IPTV STB with earlier than IPTV STB V100R003C01LMYTa6SPC001 versions has an authentication bypass vulnerability.
network
low complexity
huawei
7.5
2018-03-20 CVE-2017-17320 Double Free vulnerability in Huawei Mate 9 PRO Firmware Lonal00Bc00B139D/Lonal00Bc00B229/Lonl29Dc721B188
Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188 have a memory double free vulnerability.
local
low complexity
huawei CWE-415
7.8
2018-03-20 CVE-2017-17319 Information Exposure vulnerability in Huawei P9 Firmware
Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability.
local
low complexity
huawei CWE-200
5.5
2018-03-20 CVE-2017-17307 Out-of-bounds Read vulnerability in Huawei Vns-L21 Firmware Vnsl21Autc555B141
Some Huawei Smartphones with software of VNS-L21AUTC555B141 have an out-of-bounds read vulnerability.
local
low complexity
huawei CWE-125
5.5