VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2022-48292MedFeb 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-47974MedJan 6, 2023
    risk 0.42cvss 6.5epss 0.00

    The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerability may cause the Bluetooth process to restart.

  • CVE-2022-46740MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a denial of service vulnerability in the Wi-Fi module of the HUAWEI WS7100-20 Smart WiFi Router.Successful exploit could cause a denial of service (DoS) condition.

  • CVE-2022-41579MedDec 28, 2022
    risk 0.42cvss 6.5epss 0.00

    There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.

  • CVE-2022-33735MedSep 20, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking to obtain passwords, which may cause sensitive system information to be disclosed.

  • CVE-2022-34741MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.

  • CVE-2022-34740MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.00

    The NFC module has a buffer overflow vulnerability. Successful exploitation of this vulnerability may cause exceptions in NFC card registration, deletion, and activation.

  • CVE-2021-40016MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality.

  • CVE-2021-40013MedJul 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity.

  • CVE-2021-40059MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.00

    There is a permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2021-40042MedJan 31, 2022
    risk 0.42cvss 6.5epss 0.01

    There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process and service abnormal. Affected product versions include: CloudEngine 12800 V200R019C10SPC800, V200R019C10SPC900; CloudEngine 5800 V200R019C10SPC800,…

  • CVE-2021-40007MedDec 13, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is caused by improper log output management. An attacker with the ability to access the log file of device may lead to information disclosure.

  • CVE-2021-37039MedDec 8, 2021
    risk 0.42cvss 6.5epss 0.00

    There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS.

  • CVE-2021-39995MedNov 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi contains an out-of-bounds read vulnerability that could lead to a denial of service. Affected product versions include: eCNS280_TD V100R005C10; eSE620X vESS…

  • CVE-2021-37023MedNov 23, 2021
    risk 0.42cvss 6.5epss 0.01

    There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause media files which can be reads and writes in non-distributed directories on any device on the network..

  • CVE-2021-37124MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport…

  • CVE-2021-37122MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this vulnerability. Successful exploitation may cause the service abnormal. Affected product versions include:CloudEngine 12800…

  • CVE-2021-22382MedJun 22, 2021
    risk 0.42cvss 6.5epss 0.00

    Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerability, the attacker can perform…

  • CVE-2021-22411MedMay 27, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise…

  • CVE-2021-22339MedMay 20, 2021
    risk 0.42cvss 6.5epss 0.00

    There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal.

  • CVE-2021-22330MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.00

    There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation…

  • CVE-2021-22327MedApr 28, 2021
    risk 0.42cvss 6.5epss 0.01

    There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions…

  • CVE-2021-22312MedApr 8, 2021
    risk 0.42cvss 6.5epss 0.01

    There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service…

  • CVE-2020-9212MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.01

    There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs in to device. The attacker can exploit the vulnerability to perform some operation and can get information and cause information leak.

  • CVE-2021-22298MedFeb 6, 2021
    risk 0.42cvss 6.5epss 0.01

    There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnormal. Affected product versions…

  • CVE-2020-1866MedJan 13, 2021
    risk 0.42cvss 6.5epss 0.00

    There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions…

  • CVE-2020-1865MedJan 13, 2021
    risk 0.42cvss 6.5epss 0.00

    There is an out-of-bounds read vulnerability in Huawei CloudEngine products. The software reads data past the end of the intended buffer when parsing certain PIM message, an adjacent attacker could send crafted PIM messages to the device, successful exploit could cause out of…

  • CVE-2020-9208MedDec 29, 2020
    risk 0.42cvss 6.5epss 0.01

    There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit this vulnerability to obtain extra information, leading to information leak.

  • CVE-2020-9201MedDec 24, 2020
    risk 0.42cvss 6.5epss 0.00

    There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.

  • CVE-2020-9238MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a buffer overflow vulnerability. A function in a module does not verify inputs sufficiently. Attackers can exploit this vulnerability by sending specific request. This could compromise normal service of the affected…

  • CVE-2020-9230MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.00

    WS5800-10 version 10.0.3.25 has a denial of service vulnerability. Due to improper verification of specific message, an attacker may exploit this vulnerability to cause specific function to become abnormal.

  • CVE-2020-9122MedOct 12, 2020
    risk 0.42cvss 6.5epss 0.00

    Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abnormal on affected devices.Affected product versions include:HiRouter-CD30-10 version 10.0.2.5;HiRouter-CT31-10 version…

  • CVE-2020-9084MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.00

    Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and…

  • CVE-2020-9246MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.01

    FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some extra information. This can lead to information leak.

  • CVE-2020-9249MedJul 31, 2020
    risk 0.42cvss 6.5epss 0.00

    HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-crafted messages and it leads to memory leak. Attackers can exploit this vulnerability to make the device denial of service.Affected…

  • CVE-2020-9256MedJul 18, 2020
    risk 0.42cvss 6.5epss 0.01

    Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnerability. The system does not properly restrict the use of system service by applications, the attacker should trick the user into installing a malicious…

  • CVE-2020-9101MedJul 18, 2020
    risk 0.42cvss 6.5epss 0.00

    There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process…

  • CVE-2020-9259MedJul 17, 2020
    risk 0.42cvss 6.5epss 0.01

    Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not sufficiently validate certain parameter passed from the bottom level, the attacker should trick the user into installing a malicious…

  • CVE-2020-9260MedJul 10, 2020
    risk 0.42cvss 6.5epss 0.00

    HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain WI-FI function's default configuration in the system seems insecure, an attacker…

  • CVE-2020-1835MedJun 18, 2020
    risk 0.42cvss 6.5epss 0.00

    HUAWEI Mate 30 with versions earlier than 10.1.0.126(C00E125R5P3) have an information disclosure vulnerability. A logic judgment error occurs when the system handling Bluetooth connections, an attacker could craft as an authenticated Bluetooth peer to launch the attack.…

  • CVE-2020-9075MedJun 15, 2020
    risk 0.42cvss 6.5epss 0.01

    Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a…

  • CVE-2020-1825MedJun 15, 2020
    risk 0.42cvss 6.5epss 0.01

    FusionAccess with versions earlier than 6.5.1.SPC002 have a Denial of Service (DoS) vulnerability. Due to insufficient verification on specific input, attackers can exploit this vulnerability by sending constructed messages to the affected device through another device on the…

  • CVE-2020-9071MedJun 1, 2020
    risk 0.42cvss 6.5epss 0.01

    There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsing certain message, an authenticated attacker could exploit this vulnerability by sending crafted messages to the device.…

  • CVE-2020-9069MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.00

    There is an information leakage vulnerability in some Huawei products. An unauthenticated, adjacent attacker could exploit this vulnerability to decrypt data. Successful exploitation may leak information randomly. Affected product versions include: Anne-AL00 Versions earlier…

  • CVE-2020-1853MedFeb 17, 2020
    risk 0.42cvss 6.5epss 0.01

    GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.

  • CVE-2019-19441MedJan 3, 2020
    risk 0.42cvss 6.5epss 0.00

    HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause information leak.

  • CVE-2019-5259MedDec 16, 2019
    risk 0.42cvss 6.5epss 0.01

    There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful…

  • CVE-2019-5278MedDec 13, 2019
    risk 0.42cvss 6.5epss 0.01

    There is an out-of-bounds read vulnerability in the Advanced Packages feature of the Gauss100 OLTP database in CampusInsight before V100R019C00SPC200. Attackers who gain the specific permission can use this vulnerability by sending elaborate SQL statements to the database.…

  • CVE-2019-5260MedDec 13, 2019
    risk 0.42cvss 6.5epss 0.00

    Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected…

  • CVE-2019-5290MedDec 13, 2019
    risk 0.42cvss 6.5epss 0.01

    Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed properly, the vulnerability can be exploited to cause the device to be abnormal.

Page 28 of 48