Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8136 Information Exposure vulnerability in Huawei Hedex Lite
HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability.
local
low complexity
huawei CWE-200
5.5
2017-11-22 CVE-2017-8135 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-8134 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-8133 Command Injection vulnerability in Huawei Neteco V600R008C00/V600R008C10
Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability.
network
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-8132 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-8131 Command Injection vulnerability in Huawei Fusionsphere Openstack V100R006C00/V100R006C10
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports.
low complexity
huawei CWE-77
8.8
2017-11-22 CVE-2017-8130 Information Exposure vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has an information leak vulnerability.
network
low complexity
huawei CWE-200
6.5
2017-11-22 CVE-2017-8129 Improper Input Validation vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters.
network
low complexity
huawei CWE-20
critical
9.8
2017-11-22 CVE-2017-8128 Improper Input Validation vulnerability in Huawei UMA V200R001/V300R001
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters.
network
low complexity
huawei CWE-20
critical
9.8
2017-11-22 CVE-2017-8127 Cross-site Scripting vulnerability in Huawei UMA V200R001
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-79
6.1