Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2017-17321 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Ensp Firmware
Huawei eNSP software with software of versions earlier than V100R002C00B510 has a buffer overflow vulnerability.
local
low complexity
huawei CWE-119
3.3
2018-03-09 CVE-2017-17304 Improper Input Validation vulnerability in Huawei Dp300 Firmware
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented.
network
low complexity
huawei CWE-20
6.5
2018-03-09 CVE-2017-17303 Information Exposure vulnerability in Huawei products
Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; RP200 V500R002C00SPC200; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE30 V100R001C10SPC300; V100R001C10SPC500; V100R001C10SPC600; V100R001C10SPC700B010; V500R002C00SPC200; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC900; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE40 V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC900; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE50 V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE60 V100R001C10; V100R001C10B001; V100R001C10B002; V100R001C10B010; V100R001C10B011; V100R001C10B012; V100R001C10B013; V100R001C10B014; V100R001C10B016; V100R001C10B017; V100R001C10B018; V100R001C10B019; V100R001C10SPC400; V100R001C10SPC500; V100R001C10SPC600; V100R001C10SPC700; V100R001C10SPC800B011; V100R001C10SPC900; V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; V500R002C00SPCb00; V500R002C00SPCd00; V500R002C00SPCe00; V600R006C00; V600R006C00SPC100; V600R006C00SPC200; V600R006C00SPC300 use the CIDAM protocol, which contains sensitive information in the message when it is implemented.
network
low complexity
huawei CWE-200
4.9
2018-03-09 CVE-2017-17281 Out-of-bounds Read vulnerability in Huawei products
SFTP module in Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
4.3
2018-03-09 CVE-2017-17280 Information Exposure vulnerability in Huawei Lon-Al00B Firmware Lonal00Bc00
NFC (Near Field Communication) module in Huawei mobile phones with software LON-AL00BC00 has an information leak vulnerability.
low complexity
huawei CWE-200
3.5
2018-03-09 CVE-2017-17279 Unspecified vulnerability in Huawei Mate 9 PRO Firmware
The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-AL00B 8.0.0.343(C00) has an authentication bypass vulnerability due to the improper design of the module.
local
low complexity
huawei
5.5
2018-03-09 CVE-2017-17250 Out-of-bounds Write vulnerability in Huawei products
Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability.
network
low complexity
huawei CWE-787
6.5
2018-03-09 CVE-2017-17227 Out-of-bounds Write vulnerability in Huawei Mate 10 Firmware
GPU driver in Huawei Mate 10 smart phones with the versions before ALP-L09 8.0.0.120(C212); The versions before ALP-L09 8.0.0.127(C900); The versions before ALP-L09 8.0.0.128(402/C02/C109/C346/C432/C652) has a out-of-bounds memory access vulnerability due to the input parameters validation.
local
low complexity
huawei CWE-787
7.8
2018-03-09 CVE-2017-17225 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 9 PRO Firmware
The Near Field Communication (NFC) module in Huawei Mate 9 Pro mobile phones with the versions before LON-AL00B 8.0.0.340a(C00) has a buffer overflow vulnerability due to the lack of input validation.
low complexity
huawei CWE-119
8.8
2018-03-09 CVE-2017-17223 Path Traversal vulnerability in Huawei products
Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability.
network
low complexity
huawei CWE-22
8.8