Vulnerabilities in Huawei Technologies Co., Ltd.
380 resultsVexday analysis
O portfólio de vulnerabilidades catalogadas para a Huawei Technologies soma 380 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que indica, em termos relativos, menor pressão de exploração imediata. Ainda assim, a atenção deve recair sobre CVE-2017-17215, que apresenta EPSS de 0,7861, sinalizando alta probabilidade de exploração e permanecendo como o risco mais relevante no conjunto atual. A existência de três CVEs com prova de conceito pública reforça a necessidade de acompanhamento contínuo, mesmo na ausência de CVEs críticas formalmente classificadas ou de novas vulnerabilidades nos últimos 90 dias.
CVE-2017-8152—Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulneraEPSS 0.2%CVE-2017-17326—Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphEPSS 0.2%CVE-2017-2690—SoftCo with software V200R003C20,eSpace U1910 with software V200R003C00, V200R003C20 and V200R003C30,eSpace U1911 with software V200R003C20,EPSS 0.2%CVE-2018-7924—Anne-AL00 Huawei phones with versions earlier than 8.0.0.151(C00) have an information leak vulnerability. Due to improper permission settingEPSS 0.2%CVE-2017-8118—The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some senEPSS 0.2%CVE-2017-8173—Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlierEPSS 0.2%CVE-2018-7988—There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permissioEPSS 0.2%CVE-2018-7926—Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission coEPSS 0.2%CVE-2017-17149—Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei EPSS 0.2%CVE-2017-2727—Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier beforEPSS 0.2%CVE-2017-17329—Huawei ViewPoint 8660 V100R008C03 have a memory leak vulnerability. The software does not release allocated memory properly when parse XML SEPSS 0.2%CVE-2017-15323—Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, TE60 V100REPSS 0.2%CVE-2017-15314—Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPCEPSS 0.2%CVE-2017-17330—Huawei AR3200 V200R005C32; V200R006C10; V200R006C11; V200R007C00; V200R007C01; V200R007C02; V200R008C00; V200R008C10; V200R008C20; V200R008CEPSS 0.2%CVE-2017-8192—FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilegEPSS 0.2%CVE-2017-15307—Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulEPSS 0.2%CVE-2018-7957—Huawei smartphones with software Victoria-AL00 8.0.0.336a(C00) have an information leakage vulnerability. Because an interface does not veriEPSS 0.2%CVE-2017-17147—Huawei DP300 V500R002C00 have an integer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft speEPSS 0.2%CVE-2017-17294—Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, VEPSS 0.2%CVE-2017-17291—Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, VEPSS 0.2%