Vulnerabilidades em Huawei

1.399 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2023-52370CRITICALStack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file acEPSS 0.5%CVE-2023-52103CRITICALBuffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.EPSS 0.5%CVE-2022-39011HIGHThe HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulneEPSS 0.5%CVE-2022-48513Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-EPSS 0.5%CVE-2023-0116HIGHThe reminder module lacks an authentication mechanism for broadcasts received. Successful exploitation of this vulnerability may affect avaiEPSS 0.5%CVE-2022-38985HIGHThe facial recognition module has a vulnerability in input validation.Successful exploitation of this vulnerability may affect data confidenEPSS 0.4%CVE-2021-46839CRITICALThe HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause maliciEPSS 0.4%CVE-2021-46840CRITICALThe HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerabilitEPSS 0.4%CVE-2021-46890Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2022-46327CRITICALSome smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in sEPSS 0.4%CVE-2021-46891Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affeEPSS 0.4%CVE-2022-44551CRITICALThe iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integriEPSS 0.4%CVE-2021-46894Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalatioEPSS 0.4%CVE-2022-38998HIGHThe HISP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability EPSS 0.4%CVE-2022-41581CRITICALThe HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause maliciousEPSS 0.4%CVE-2022-38984HIGHThe HIPP module has a vulnerability of not verifying the data transferred in the kernel space.Successful exploitation of this vulnerability EPSS 0.4%CVE-2022-41586HIGHThe communication framework module has a vulnerability of not truncating data properly.Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2023-37242Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite thEPSS 0.4%CVE-2022-38981HIGHThe HwAirlink module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause information leakage.EPSS 0.4%CVE-2021-37082There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.EPSS 0.4%