Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2017-04-02 CVE-2016-8272 Information Exposure vulnerability in Huawei Hisuite 4.0.5.300Ove
Huawei PC client software HiSuite 4.0.5.300_OVE has an information leak vulnerability; an attacker who can log in to the system can copy out the user's proxy password, causing information leaks.
local
low complexity
huawei CWE-200
5.3
2017-04-02 CVE-2016-8271 Information Exposure vulnerability in Huawei Espace IAD Firmware V300R001C07Spca00/V300R002C01/V300R002C01Spc100
Huawei eSpace IAD V300R002C01SPC100 and earlier versions have an information leak vulnerability; an attacker can check and download the fault information by accessing a special URL.
network
low complexity
huawei CWE-200
5.3
2017-04-02 CVE-2016-6177 Integer Overflow or Wraparound vulnerability in Huawei Oceanstor 5800 V3 Firmware V300R003C00
The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability.
network
low complexity
huawei CWE-190
6.5
2017-04-02 CVE-2016-2404 Permissions, Privileges, and Access Controls vulnerability in Huawei products
Huawei switches S5700, S6700, S7700, S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300, V200R005C00SPC500, V200R006C00; S12700 with software V200R005C00SPC500, V200R006C00; ACU2 with software V200R005C00SPC500, V200R006C00 have a permission control vulnerability.
network
high complexity
huawei CWE-264
7.5
2017-04-02 CVE-2015-8671 Permissions, Privileges, and Access Controls vulnerability in Huawei Logcenter V100R001C10
Huawei LogCenter V100R001C10 could allow an authenticated attacker to tamper with requests using a tool and submit a request to the server for privilege escalation, affecting some system functions.
network
low complexity
huawei CWE-264
8.8
2017-04-02 CVE-2015-8670 Improper Input Validation vulnerability in Huawei Logcenter V100R001C10
Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collection module, causing denial of service.
network
low complexity
huawei CWE-20
6.5
2017-04-02 CVE-2015-7847 Improper Input Validation vulnerability in Huawei E3272S Firmware
Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 has a Denial of Service (DoS) vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-04-02 CVE-2015-7844 Improper Input Validation vulnerability in Huawei Fusionaccess V100R005C10/V100R005C20
Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protocol packet to cause the virtual cloud desktop to be displaying an error and not usable.
network
low complexity
huawei CWE-20
7.5
2017-04-02 CVE-2015-2246 Information Exposure vulnerability in Huawei P7-L10 Firmware V100R001C00B136
The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the disclosure of contact information.
local
low complexity
huawei CWE-200
3.3
2017-04-02 CVE-2014-9696 Permissions, Privileges, and Access Controls vulnerability in Huawei Tecal E9000 Chassis Firmware V100R001C00Spc160
The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions allows the operator to modify the user configuration of iMana through privilege escalation.
network
low complexity
huawei CWE-264
8.8