Vulnerabilities > Huawei > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-09-07 CVE-2016-6825 Improper Authorization vulnerability in Huawei products
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms."
network
low complexity
huawei CWE-285
critical
9.8
2016-08-02 CVE-2016-6178 Improper Input Validation vulnerability in Huawei products
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.
network
low complexity
huawei CWE-20
critical
9.8
2016-06-14 CVE-2016-5365 Permissions, Privileges, and Access Controls vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.
network
low complexity
huawei CWE-264
critical
9.8
2016-05-23 CVE-2016-4576 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
network
low complexity
huawei CWE-119
critical
9.8
2016-02-15 CVE-2016-2231 Data Processing Errors vulnerability in Huawei Mt882 Firmware V200R002B022
The Windows-based Host Interface Program (WHIP) service on Huawei SmartAX MT882 devices V200R002B022 Arg relies on the client to send a length field that is consistent with a buffer size, which allows remote attackers to cause a denial of service (device outage) or possibly have unspecified other impact via crafted traffic on TCP port 8701.
network
low complexity
huawei CWE-19
critical
9.8