Vulnerabilities > Huawei > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-27 CVE-2018-7958 Improper Authentication vulnerability in Huawei Espace 7950 Firmware V200R003C30
There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product.
network
high complexity
huawei CWE-287
7.4
2018-09-12 CVE-2018-7923 Improper Input Validation vulnerability in Huawei Alp-L09 Firmware
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check.
local
low complexity
huawei CWE-20
7.8
2018-09-12 CVE-2018-7922 Improper Input Validation vulnerability in Huawei Alp-L09 Firmware
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check.
local
low complexity
huawei CWE-20
7.8
2018-09-04 CVE-2018-7937 Unspecified vulnerability in Huawei Hirouter-Cd20 Firmware and Ws5200-10 Firmware
In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification.
local
low complexity
huawei
7.8
2018-08-21 CVE-2017-17312 Improper Input Validation vulnerability in Huawei products
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products.
network
low complexity
huawei CWE-20
7.5
2018-08-21 CVE-2017-17311 Improper Input Validation vulnerability in Huawei products
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a DoS vulnerability in the IPSEC IKEv1 implementations of Huawei Firewall products.
network
low complexity
huawei CWE-20
7.5
2018-07-31 CVE-2018-7994 Missing Release of Resource after Effective Lifetime vulnerability in Huawei products
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability.
network
low complexity
huawei CWE-772
7.5
2018-07-31 CVE-2018-7993 Use After Free vulnerability in Huawei Mate 10 Firmware
HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component.
local
low complexity
huawei CWE-416
7.8
2018-06-14 CVE-2017-17309 Path Traversal vulnerability in Huawei Hg255S-10 Firmware V100R001C163B025Sp02
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
network
low complexity
huawei CWE-22
7.5
2018-06-14 CVE-2017-17173 Improper Input Validation vulnerability in Huawei Mate 9 PRO Fimware Lonal00B8.0.0.334(C00)/Lonal00B8.0.0.340A(C00)
Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability.
local
low complexity
huawei CWE-20
7.8