Vulnerabilidades em Huawei

1.399 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2021-46787The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system applicaEPSS 0.7%CVE-2021-37041There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds rEPSS 0.7%CVE-2021-37063There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to read and deleteEPSS 0.7%CVE-2021-37116PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of tEPSS 0.7%CVE-2021-37042There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds rEPSS 0.7%CVE-2021-37059There is a Weaknesses Introduced During DesignEPSS 0.7%CVE-2021-22480The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead toEPSS 0.7%CVE-2021-37065There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to ConfiEPSS 0.7%CVE-2021-22448There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read anEPSS 0.7%CVE-2020-9094There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with specific message proEPSS 0.7%CVE-2021-40056There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerabiEPSS 0.7%CVE-2021-40062There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitation of this vulnerabiEPSS 0.7%CVE-2020-1830Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001CEPSS 0.7%CVE-2021-40063There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may affect confidentialEPSS 0.7%CVE-2021-22473There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentialiEPSS 0.7%CVE-2019-5299Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. AttackersEPSS 0.7%CVE-2022-22254A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confiEPSS 0.7%CVE-2020-1853GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker EPSS 0.7%CVE-2021-36990There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permisEPSS 0.7%CVE-2021-22389There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to beEPSS 0.7%