Vulnerabilities > Huawei > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-31 CVE-2018-7994 Missing Release of Resource after Effective Lifetime vulnerability in Huawei products
Some Huawei products IPS Module V500R001C50; NGFW Module V500R001C50; V500R002C10; NIP6300 V500R001C50; NIP6600 V500R001C50; NIP6800 V500R001C50; Secospace USG6600 V500R001C50; USG9500 V500R001C50 have a memory leak vulnerability.
network
low complexity
huawei CWE-772
7.5
2018-07-31 CVE-2018-7993 Use After Free vulnerability in Huawei Mate 10 Firmware
HUAWEI Mate 10 smartphones with versions earlier than ALP-AL00 8.1.0.311 have a use after free vulnerability on mediaserver component.
local
low complexity
huawei CWE-416
7.8
2018-06-14 CVE-2017-17309 Path Traversal vulnerability in Huawei Hg255S-10 Firmware V100R001C163B025Sp02
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.
network
low complexity
huawei CWE-22
7.5
2018-06-14 CVE-2017-17173 Improper Input Validation vulnerability in Huawei Mate 9 PRO Fimware Lonal00B8.0.0.334(C00)/Lonal00B8.0.0.340A(C00)
Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability.
local
low complexity
huawei CWE-20
7.8
2018-06-14 CVE-2017-17172 Improper Handling of Exceptional Conditions vulnerability in Huawei Lyo-L21
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability.
local
low complexity
huawei CWE-755
7.3
2018-06-05 CVE-2018-7943 Improper Authentication vulnerability in Huawei products
There is an authentication bypass vulnerability in some Huawei servers.
network
low complexity
huawei CWE-287
8.8
2018-06-01 CVE-2018-7951 Code Injection vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-94
8.8
2018-06-01 CVE-2018-7950 Code Injection vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation.
network
low complexity
huawei CWE-94
8.8
2018-06-01 CVE-2018-7949 Improper Authentication vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability.
network
low complexity
huawei CWE-287
8.8
2018-05-24 CVE-2018-7942 Unspecified vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerability.
network
low complexity
huawei
7.5