Vulnerabilidades em Huawei Technologies Co., Ltd.
380 resultadosAnálise Vexday
O portfólio de vulnerabilidades catalogadas para a Huawei Technologies soma 380 CVEs, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada confirmada no CISA KEV —, o que indica, em termos relativos, menor pressão de exploração imediata. Ainda assim, a atenção deve recair sobre CVE-2017-17215, que apresenta EPSS de 0,7861, sinalizando alta probabilidade de exploração e permanecendo como o risco mais relevante no conjunto atual. A existência de três CVEs com prova de conceito pública reforça a necessidade de acompanhamento contínuo, mesmo na ausência de CVEs críticas formalmente classificadas ou de novas vulnerabilidades nos últimos 90 dias.
CVE-2017-17298—Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, VEPSS 0.8%CVE-2018-7956—Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20. There is a vulnerability in versionsEPSS 0.8%CVE-2017-15341—Huawei AR3200 V200R008C20, V200R008C30, TE40 V600R006C00, TE50 V600R006C00, TE60 V600R006C00 have a denial of service vulnerability. The sofEPSS 0.8%CVE-2017-17303—Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00BEPSS 0.8%CVE-2017-8121—The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some senEPSS 0.7%CVE-2017-17319—Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not propeEPSS 0.7%CVE-2017-17328—Huawei smartphones with software of MHA-AL00AC00B125 have an integer overflow vulnerability. The software does not process certain variable EPSS 0.7%CVE-2017-2696—The emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions has a buffer overflow vulnerability. An aEPSS 0.7%CVE-2017-2716—The camerafs driver in Mate 9 Versions earlier than MHA-AL00BC00B173 has buffer overflow vulnerability. An attacker tricks a user into instaEPSS 0.7%CVE-2017-17199—Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V5EPSS 0.7%CVE-2017-17200—Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V5EPSS 0.7%CVE-2017-8162—AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R00EPSS 0.7%CVE-2017-8130—The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some senEPSS 0.7%CVE-2018-7987—There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle thEPSS 0.7%CVE-2017-17314—Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V6EPSS 0.7%CVE-2017-8137—HedEx Earlier than V200R006C00 versions has a dynamic link library (DLL) hijacking vulnerability due to calling the DDL file by accessing a EPSS 0.7%CVE-2017-15311—The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), beforeEPSS 0.7%CVE-2017-15310—Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploiEPSS 0.7%CVE-2017-2720—FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messEPSS 0.7%CVE-2017-17141—Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009C00;S1700 V200R006C10; V200R009C00;S2700EPSS 0.7%