Vulnerabilities > Huawei > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-07-05 CVE-2018-7944 Unspecified vulnerability in Huawei Emily-Al00A Firmware 8.1.0.106(Sp2C00)/8.1.0.107(Sp5C00)
Huawei smart phones Emily-AL00A with software 8.1.0.106(SP2C00) and 8.1.0.107(SP5C00) have a Factory Reset Protection (FRP) bypass vulnerability.
low complexity
huawei
6.8
2018-07-02 CVE-2017-17316 Out-of-bounds Read vulnerability in Huawei products
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
5.3
2018-07-02 CVE-2017-17175 Improper Input Validation vulnerability in Huawei Mate 9 PRO Lonal00B8.0.0.334(C00)/Lonal00B8.0.0.340A(C00)/Lonal00B8.0.0.343(C00)
Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability.
low complexity
huawei CWE-20
6.5
2018-06-01 CVE-2018-7976 Cross-site Scripting vulnerability in Huawei Espace Desktop 300R001C00/300R001C50
There is a stored cross-site scripting (XSS) vulnerability in Huawei eSpace Desktop V300R001C00 and V300R001C50 version.
network
low complexity
huawei CWE-79
5.4
2018-06-01 CVE-2017-17171 Improper Input Validation vulnerability in Huawei Mate 8 Firmware and P9 Firmware
Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious parameters.
local
low complexity
huawei CWE-20
4.2
2018-05-24 CVE-2017-17315 Improper Input Validation vulnerability in Huawei products
Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have a numeric errors vulnerability.
network
low complexity
huawei CWE-20
5.3
2018-05-24 CVE-2017-17158 Improper Input Validation vulnerability in Huawei products
Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability.
low complexity
huawei CWE-20
4.6
2018-05-10 CVE-2018-7940 Improper Authentication vulnerability in Huawei Mate 9 Firmware and Mate 9 PRO Firmware
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability.
low complexity
huawei CWE-287
6.2
2018-04-30 CVE-2018-7901 Unspecified vulnerability in Huawei Alp-Al00B Firmware and Bla-Al00B Firmware
RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability.
local
low complexity
huawei
4.4
2018-04-30 CVE-2017-17318 Improper Input Validation vulnerability in Huawei E5771H-937 Firmware V200R001B328D62Sp00C1133
Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability.
low complexity
huawei CWE-20
6.5