Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2016-06-30 CVE-2016-4086 Unspecified vulnerability in Huawei Hisuite
Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.
high complexity
huawei
5.3
2016-06-30 CVE-2016-4057 Resource Management Errors vulnerability in Huawei Fusioncompute V100R005C00
Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.
network
low complexity
huawei CWE-399
6.5
2016-06-24 CVE-2016-5723 Permissions, Privileges, and Access Controls vulnerability in Huawei Fusioninsight HD V100R002C30/V100R002C50
Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors.
local
low complexity
huawei CWE-264
7.8
2016-06-24 CVE-2016-5722 Information Exposure vulnerability in Huawei Ocean Stor Firmware
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniffing the network.
network
low complexity
huawei CWE-200
7.3
2016-06-24 CVE-2016-5435 Resource Management Errors vulnerability in Huawei Firmware V5500R001C00
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause a denial of service (memory consumption and reboot) via a crafted packet.
network
high complexity
huawei CWE-399
5.9
2016-06-14 CVE-2016-5367 Information Exposure vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053.
network
low complexity
huawei CWE-200
7.5
2016-06-14 CVE-2016-5366 Improper Access Control vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
network
low complexity
huawei CWE-284
7.5
2016-06-14 CVE-2016-5365 Permissions, Privileges, and Access Controls vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.
network
low complexity
huawei CWE-264
critical
9.8
2016-06-13 CVE-2016-5234 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Rse6500 Firmware and Vp9600 Series Firmware
Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.
network
high complexity
huawei CWE-119
8.1
2016-06-13 CVE-2016-4005 Cryptographic Issues vulnerability in Huawei Hilink APP 3.19.1
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
local
low complexity
huawei CWE-310
5.5