Vulnerabilities in Huawei

1,367 results
Vexday analysis

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2020-9236HIGHThere is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some opeEPSS 0.4%CVE-2023-39402CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.4%CVE-2023-39401CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.4%CVE-2023-39400CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.4%CVE-2022-48361The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerability may cause a faiEPSS 0.4%CVE-2022-48350HIGHThe HUAWEI Messaging app has a vulnerability of unauthorized file access. Successful exploitation of this vulnerability may affect confidentEPSS 0.4%CVE-2022-44549HIGHThe LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to accEPSS 0.4%CVE-2023-41294The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.EPSS 0.4%CVE-2022-44557HIGHThe SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploEPSS 0.4%CVE-2022-48360The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerability may affect confiEPSS 0.4%CVE-2023-44118Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confEPSS 0.4%CVE-2022-46328HIGHSome smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.4%CVE-2022-48312CRITICALThe HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiEPSS 0.4%CVE-2022-41599HIGHThe system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data coEPSS 0.4%CVE-2021-46867HIGHThe HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory aEPSS 0.4%CVE-2022-48297HIGHThe geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability EPSS 0.4%CVE-2021-46868HIGHThe HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory aEPSS 0.4%CVE-2022-46321HIGHThe Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentialiEPSS 0.4%CVE-2022-48298HIGHThe geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounEPSS 0.4%CVE-2023-44108HIGHType confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.4%