Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2016-09-22 CVE-2016-6824 Improper Input Validation vulnerability in Huawei products
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP packets.
network
low complexity
huawei CWE-20
6.5
2016-09-22 CVE-2016-6669 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitrary code by sending a crafted EAP packet.
network
high complexity
huawei CWE-119
7.5
2016-09-21 CVE-2016-6159 Improper Authentication vulnerability in Huawei Ws331A Router Firmware Ws331A10V100R001C02B017Sp01
The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special packages" to the LAN interface.
high complexity
huawei CWE-287
7.5
2016-09-21 CVE-2016-6158 Cross-Site Request Forgery (CSRF) vulnerability in Huawei Ws331A Router Firmware Ws331A10V100R001C02B017Sp01
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via unspecified vectors.
network
low complexity
huawei CWE-352
6.1
2016-09-07 CVE-2016-6179 Improper Access Control vulnerability in Huawei Honor 6 Firmware
The WiFi driver in Huawei Honor 6 smartphones with software H60-L01 before H60-L01C00B850, H60-L11 before H60-L11C00B850, H60-L21 before H60-L21C00B850, H60-L02 before H60-L02C00B850, H60-L12 before H60-L12C00B850, and H60-L03 before H60-L03C01B850 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application.
local
high complexity
huawei CWE-284
7.0
2016-09-07 CVE-2016-7110 Code Injection vulnerability in Huawei UMA V200R001/V200R001C00Spc100
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7109.
network
low complexity
huawei CWE-94
critical
9.8
2016-09-07 CVE-2016-7109 Code Injection vulnerability in Huawei UMA V200R001/V200R001C00Spc100
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110.
network
low complexity
huawei CWE-94
critical
9.8
2016-09-07 CVE-2016-7108 Information Exposure vulnerability in Huawei UMA V200R001/V200R001C00Spc100/V200R001C00Spc200
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.
network
low complexity
huawei CWE-200
6.5
2016-09-07 CVE-2016-7107 Improper Access Control vulnerability in Huawei UMA V200R001/V200R001C00Spc100/V200R001C00Spc200
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently affect system data integrity via unspecified vectors.
network
low complexity
huawei CWE-284
7.5
2016-09-07 CVE-2016-6900 Resource Management Errors vulnerability in Huawei products
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613; RH2288 V3 servers with software before V100R003C00SPC617; RH2288H V3 servers with software before V100R003C00SPC515; RH5885 V3 servers with software before V100R003C10SPC102; and XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610 allows local users to cause a denial of service (iBMC resource consumption) via unspecified vectors.
local
low complexity
huawei CWE-399
5.5