Vulnerabilities > Huawei > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2017-17327 Unspecified vulnerability in Huawei Mha-Al00A Firmware Mhaal00Ac00B125
Huawei smartphones with software of MHA-AL00AC00B125 have an improper resource management vulnerability.
local
low complexity
huawei
5.5
2018-03-09 CVE-2017-17326 Unspecified vulnerability in Huawei Mate 9 PRO Fimware Lonal00Bc00B139D/Lonal00Bc00B229
Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability.
low complexity
huawei
4.6
2018-03-09 CVE-2017-17323 Incorrect Authorization vulnerability in Huawei Ibmc Firmware V200R002C10/V200R002C20/V200R002C30
Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability.
network
low complexity
huawei CWE-863
4.3
2018-03-09 CVE-2017-17322 Information Exposure vulnerability in Huawei Honor Smart Scale Application Firmware 1.1.1
Huawei Honor Smart Scale Application with software of 1.1.1 has an information disclosure vulnerability.
network
low complexity
huawei CWE-200
4.3
2018-03-09 CVE-2017-17304 Improper Input Validation vulnerability in Huawei Dp300 Firmware
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented.
network
low complexity
huawei CWE-20
6.5
2018-03-09 CVE-2017-17303 Information Exposure vulnerability in Huawei products
Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; RP200 V500R002C00SPC200; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE30 V100R001C10SPC300; V100R001C10SPC500; V100R001C10SPC600; V100R001C10SPC700B010; V500R002C00SPC200; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC900; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE40 V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC900; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE50 V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPCb00; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE60 V100R001C10; V100R001C10B001; V100R001C10B002; V100R001C10B010; V100R001C10B011; V100R001C10B012; V100R001C10B013; V100R001C10B014; V100R001C10B016; V100R001C10B017; V100R001C10B018; V100R001C10B019; V100R001C10SPC400; V100R001C10SPC500; V100R001C10SPC600; V100R001C10SPC700; V100R001C10SPC800B011; V100R001C10SPC900; V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC600; V500R002C00SPC700; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; V500R002C00SPCb00; V500R002C00SPCd00; V500R002C00SPCe00; V600R006C00; V600R006C00SPC100; V600R006C00SPC200; V600R006C00SPC300 use the CIDAM protocol, which contains sensitive information in the message when it is implemented.
network
low complexity
huawei CWE-200
4.9
2018-03-09 CVE-2017-17281 Out-of-bounds Read vulnerability in Huawei products
SFTP module in Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability.
network
low complexity
huawei CWE-125
4.3
2018-03-09 CVE-2017-17279 Unspecified vulnerability in Huawei Mate 9 PRO Firmware
The soundtrigger module in Huawei Mate 9 Pro smart phones with software of the versions before LON-AL00B 8.0.0.343(C00) has an authentication bypass vulnerability due to the improper design of the module.
local
low complexity
huawei
5.5
2018-03-09 CVE-2017-17250 Out-of-bounds Write vulnerability in Huawei products
Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-bounds write vulnerability.
network
low complexity
huawei CWE-787
6.5
2018-03-09 CVE-2017-17220 Out-of-bounds Read vulnerability in Huawei products
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities.
network
low complexity
huawei CWE-125
5.3