Vulnerabilities > Huawei > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-11-22 CVE-2017-8158 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Fusioncompute V100R005C00/V100R005C10
FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine.
local
low complexity
huawei CWE-732
6.5
2017-11-22 CVE-2017-8157 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Huawei products
OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability.
network
high complexity
huawei CWE-327
5.9
2017-11-22 CVE-2017-8156 Missing Authentication for Critical Function vulnerability in Huawei B2338-168 Firmware V100R001C00
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port.
low complexity
huawei CWE-306
6.8
2017-11-22 CVE-2017-8152 Improperly Implemented Security Check for Standard vulnerability in Huawei Honor 5S Firmware
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design.
low complexity
huawei CWE-358
4.6
2017-11-22 CVE-2017-8151 Improper Authentication vulnerability in Huawei Honor 5S Firmware
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have an authentication bypass vulnerability due to the improper design of some components.
low complexity
huawei CWE-287
6.8
2017-11-22 CVE-2017-8149 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei P10 Firmware and P10 Plus Firmware
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an out-of-bounds memory access vulnerability due to the lack of parameter validation.
local
low complexity
huawei CWE-119
5.5
2017-11-22 CVE-2017-8148 Race Condition vulnerability in Huawei P9 Firmware
Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability.
local
high complexity
huawei CWE-362
4.7
2017-11-22 CVE-2017-8146 Improper Input Validation vulnerability in Huawei P10 Firmware and P10 Plus Firmware
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8145 Improper Input Validation vulnerability in Huawei P10 Firmware and P10 Plus Firmware
The call module of P10 and P10 Plus smartphones with software versions before VTR-AL00C00B167, versions before VTR-TL00C01B167, versions before VKY-AL00C00B167, versions before VKY-TL00C01B167 has a DoS vulnerability.
local
low complexity
huawei CWE-20
5.5
2017-11-22 CVE-2017-8144 Improper Restriction of Power Consumption vulnerability in Huawei products
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting.
local
low complexity
huawei CWE-920
5.5