Vulnerabilidades em huawei

1.400 resultados
Análise Vexday

Huawei apresenta um volume mínimo de vulnerabilidades rastreadas (1 CVE), sem registros de exploração ativa nem críticas de severidade elevada. A única fragilidade catalogada refere-se a validação inadequada de entrada (CWE-20), com nenhuma publicação recente nos últimos 90 dias, indicando um panorama de risco baixo e estável no curto prazo.

CVE-2022-39006—The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.EPSS 0.4%CVE-2022-46313MEDIUMThe sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause unavailability of theEPSS 0.4%CVE-2019-5280—The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verEPSS 0.4%CVE-2023-0117MEDIUMThe online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of thisEPSS 0.4%CVE-2023-52369CRITICALStack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.EPSS 0.4%CVE-2023-46755MEDIUMVulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launEPSS 0.4%CVE-2023-6273MEDIUMPermission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause featuEPSS 0.4%CVE-2023-41301—Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnoEPSS 0.4%CVE-2020-9236HIGHThere is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some opeEPSS 0.4%CVE-2022-48289HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2022-48294HIGHThe IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%CVE-2022-48288HIGHThe bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affEPSS 0.4%CVE-2022-48299HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2022-48300HIGHThe WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentialitEPSS 0.4%CVE-2024-32989LOWInsufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affecEPSS 0.4%CVE-2023-39384—Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause featEPSS 0.4%CVE-2022-47976HIGHThe DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of thisEPSS 0.4%CVE-2023-39380—Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnorEPSS 0.4%CVE-2020-1814—Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001CEPSS 0.4%CVE-2022-38977HIGHThe HwAirlink module has a heap overflow vulnerability.Successful exploitation of this vulnerability may cause out-of-bounds writes, resultiEPSS 0.4%