Vulnerabilidades em HUAWEI
1.400 resultadosAnálise Vexday
A Huawei apresenta um perfil de risco baixo na base do Vexday, com apenas 5 CVEs registradas e nenhuma sob exploração ativa (KEV). Não há vulnerabilidades críticas identificadas nem publicações recentes, indicando estabilidade relativa no período analisado.
CVE-2023-26549—The SystemUI module has a vulnerability of repeated app restart due to improper parameters. Successful exploitation of this vulnerability maEPSS 0.4%CVE-2023-49239—Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiEPSS 0.4%CVE-2023-49247—Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiaEPSS 0.4%CVE-2023-49246HIGHUnauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiEPSS 0.4%CVE-2023-46771HIGHSecurity vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2023-46759—Permission control vulnerability in the call module. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2023-49240—Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2023-44113HIGHVulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnEPSS 0.4%CVE-2022-46313MEDIUMThe sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of theEPSS 0.4%CVE-2022-39006—The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.4%CVE-2019-5280—The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verEPSS 0.4%CVE-2023-0117MEDIUMThe online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of thisEPSS 0.4%CVE-2023-6273MEDIUMPermission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause featuEPSS 0.4%CVE-2023-52369CRITICALStack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%CVE-2023-46755MEDIUMVulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launEPSS 0.4%CVE-2020-9236HIGHThere is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some opeEPSS 0.4%CVE-2022-48299HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2022-48294HIGHThe IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2022-48288HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2022-48300HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%