Vulnerabilidades em Huawei

1.378 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2019-5285Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send crafted packets to the affected device tEPSS 1.7%CVE-2019-19398M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorreEPSS 1.4%CVE-2021-37095There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remotEPSS 1.4%CVE-2022-48616MEDIUMA Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackersEPSS 1.2%CVE-2022-32203CRITICALThere is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privilegeEPSS 1.1%CVE-2020-1811GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low peEPSS 1.1%CVE-2018-7935MEDIUM There is a vulnerability in 21.328.01.00.00 version of the E5573Cs-322. Remote attackers could exploit this vulnerability to make the netwoEPSS 1.1%CVE-2020-1790GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input froEPSS 1.1%CVE-2021-40050There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.EPSS 1.1%CVE-2020-9068Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have aEPSS 1.1%CVE-2022-48472CRITICALA Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected productEPSS 1.1%CVE-2021-39979HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.EPSS 1.1%CVE-2019-5242There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to inEPSS 1.0%CVE-2019-5284There is a DoS vulnerability in RTSP module of Leland-AL00A Huawei smart phones versions earlier than Leland-AL00A 9.1.0.111(C00E111R2P10T8)EPSS 1.0%CVE-2020-1841Huawei CloudLink Board version 20.0.0; DP300 version V500R002C00; RSE6500 versions V100R001C00, V500R002C00, and V500R002C00SPC900; and TE60EPSS 1.0%CVE-2021-40014The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data EPSS 1.0%CVE-2021-22387There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulneEPSS 0.9%CVE-2019-5223PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation oEPSS 0.9%CVE-2020-1863Huawei USG6000V with versions V500R001C20SPC300, V500R003C00SPC100, and V500R005C00SPC100 have an out-of-bounds read vulnerability. Due to aEPSS 0.9%CVE-2021-37022There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause root permiEPSS 0.9%