Vulnerabilidades em Huawei

1.399 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2019-5237Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. SucceEPSS 0.9%CVE-2020-1816Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001CEPSS 0.9%CVE-2021-39994There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect EPSS 0.9%CVE-2022-39001HIGHThe number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosureEPSS 0.9%CVE-2019-5266Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit thiEPSS 0.9%CVE-2021-22430There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.EPSS 0.9%CVE-2021-40027The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confEPSS 0.8%CVE-2021-22394There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during MultEPSS 0.8%CVE-2021-40012Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerabilEPSS 0.8%CVE-2022-34742The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.8%CVE-2019-5241There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a userEPSS 0.8%CVE-2021-37064There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vuEPSS 0.8%CVE-2021-37088There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write aEPSS 0.8%CVE-2021-37087There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create EPSS 0.8%CVE-2020-9247There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parametEPSS 0.8%CVE-2021-37126Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerabilityEPSS 0.8%CVE-2021-40064There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability may affect system stEPSS 0.8%CVE-2021-40065The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentialiEPSS 0.8%CVE-2021-39997There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may caEPSS 0.8%CVE-2020-9259Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system doEPSS 0.8%