Vulnerabilities > Huawei > Usg9500 Firmware > v500r005c00

DATE CVE VULNERABILITY TITLE RISK
2020-02-28 CVE-2020-1860 Improper Input Validation vulnerability in Huawei products
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability.
network
low complexity
huawei CWE-20
5.0
2020-02-18 CVE-2020-1814 NULL Pointer Dereference vulnerability in Huawei products
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability.
network
huawei CWE-476
3.5
2020-02-18 CVE-2020-1830 Out-of-bounds Read vulnerability in Huawei products
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a vulnerability that a memory management error exists when IPSec Module handing a specific message.
network
low complexity
huawei CWE-125
5.0
2020-02-18 CVE-2020-1816 Improper Input Validation vulnerability in Huawei products
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Denial of Service (DoS) vulnerability.
network
huawei CWE-20
4.3
2020-02-18 CVE-2020-1815 Missing Release of Resource after Effective Lifetime vulnerability in Huawei products
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability.
network
huawei CWE-772
4.3
2020-02-17 CVE-2020-1856 Information Exposure vulnerability in Huawei products
Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V500R005C00 have an information leakage vulnerability.
network
low complexity
huawei CWE-200
5.0
2020-02-17 CVE-2020-1828 Improper Input Validation vulnerability in Huawei products
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message.
network
low complexity
huawei CWE-20
5.0