|
196701
|
6.5 |
MEDIUM
Network
|
huawei
|
imanager_neteco_6000
|
There is an information leak vulnerability in iManager NetEco 6000 versions V600R021C00. A module is lack of authentication. Attackers without access to the module can exploit this vulnerability to o…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9208
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196702
|
7.8 |
HIGH
Local
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is an improper authentication vulnerability in some verisons of Huawei CloudEngine product. A module does not verify the input file properly. Attackers can exploit this vulnerability by craftin…
|
CWE-287
Improper Authentication
|
CVE-2020-9207
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196703
|
6.7 |
MEDIUM
Local
|
huawei
|
mate_30_firmware
|
There is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2). An attacker with specific permission can exploit this vulnerability by sending…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9125
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196704
|
7.5 |
HIGH
Network
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is a memory leak vulnerability in some versions of Huawei CloudEngine product. An unauthenticated, remote attacker may exploit this vulnerability by sending specific message to the affected pro…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-9124
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196705
|
7.5 |
HIGH
Network
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is an out of bound read vulnerability in some verisons of Huawei CloudEngine product. A module does not deal with specific message properly. Attackers can exploit this vulnerability by sending …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9094
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196706
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-al00a_firmware
|
There is a use after free vulnerability in Taurus-AL00A versions 10.0.0.1(C00E1R1P1). A module does not deal with specific message properly, which makes a function refer to memory after it has been f…
|
CWE-416
Use After Free
|
CVE-2020-9093
|
2024-11-21 14:40 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196707
|
4.4 |
MEDIUM
Local
|
huawei
|
te_mobile
|
There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attack…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2020-9202
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196708
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
nip6800_firmware secospace_usg6600_firmware usg9500_firmware
|
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages includi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-9201
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196709
|
7.8 |
HIGH
Local
|
huawei
|
imanager_neteco_6000
|
There has a CSV injection vulnerability in iManager NetEco 6000 versions V600R021C00. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files.…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9200
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196710
|
6.7 |
MEDIUM
Local
|
huawei
|
cloudengine_12800_firmware cloudengine_5800_firmware cloudengine_6800_firmware cloudengine_7800_firmware
|
There is a privilege escalation vulnerability in some versions of CloudEngine 12800,CloudEngine 5800,CloudEngine 6800 and CloudEngine 7800. Due to insufficient input validation, a local attacker with…
|
CWE-20
Improper Input Validation
|
CVE-2020-9137
|
2024-11-21 14:40 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|