Vulnerabilidades em Huawei

1.400 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2021-46867HIGHThe HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory aEPSS 0.4%CVE-2022-41599HIGHThe system service has a vulnerability that causes incorrect return values. Successful exploitation of this vulnerability may affect data coEPSS 0.4%CVE-2022-46328HIGHSome smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.4%CVE-2022-48516Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation of this vulnerabilityEPSS 0.4%CVE-2023-39385Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unaEPSS 0.4%CVE-2022-48297HIGHThe geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of this vulnerability EPSS 0.4%CVE-2023-39383Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromisEPSS 0.4%CVE-2022-46321HIGHThe Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentialiEPSS 0.4%CVE-2023-39391Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confideEPSS 0.4%CVE-2022-48298HIGHThe geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability may cause out-of-bounEPSS 0.4%CVE-2021-46868HIGHThe HW_KEYMASTER module has a problem in releasing memory.Successful exploitation of this vulnerability may result in out-of-bounds memory aEPSS 0.4%CVE-2022-48606Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may afEPSS 0.4%CVE-2023-44095Use-After-Free (UAF) vulnerability in the surfaceflinger module.Successful exploitation of this vulnerability can cause system crash.EPSS 0.4%CVE-2023-44108HIGHType confusion vulnerability in the distributed file module.Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.4%CVE-2023-52540HIGHVulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availabilitEPSS 0.4%CVE-2022-48480HIGHInteger overflow vulnerability in some phones. Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.4%CVE-2022-46310HIGHThe TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentEPSS 0.4%CVE-2023-44107 Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability mayEPSS 0.4%CVE-2022-48514The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confEPSS 0.4%CVE-2017-17224Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attEPSS 0.4%