|
202291
|
6.5 |
MEDIUM
Adjacent
|
huawei
|
hirouter-cd30-10_firmware hirouter-ct31-10_firmware ws5200-12_firmware ws5281-10_firmware ws5800-10_firmware ws7100-10_firmware ws7200-10_firmware
|
Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abnormal on affected devices.Affected product versions…
|
CWE-20
Improper Input Validation
|
CVE-2020-9122
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202292
|
4.6 |
MEDIUM
Physics
|
huawei
|
mate_20_firmware mate_20_x_firmware p30_pro_firmware laya-al00ep_firmware tony-al00b_firmware tony-tl00b_firmware
|
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker nee…
|
CWE-287
Improper Authentication
|
CVE-2020-9109
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202293
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9108
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202294
|
5.5 |
MEDIUM
Local
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9107
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202295
|
4.6 |
MEDIUM
Physics
|
huawei
|
p30_pro_firmware
|
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attack…
|
CWE-22
Path Traversal
|
CVE-2020-9106
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202296
|
5.5 |
MEDIUM
Local
|
huawei
|
taurus-an00b_firmware
|
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an out-of-bounds read and write vulnerability. Some functions do not verify inputs sufficiently. Attackers can exploit this vulnerabili…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-9091
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202297
|
7.8 |
HIGH
Local
|
huawei
|
fusionaccess
|
FusionAccess version 6.5.1 has an improper authorization vulnerability. A command is authorized with incorrect privilege. Attackers with other privilege can execute the command to exploit this vulner…
|
NVD-CWE-noinfo
|
CVE-2020-9090
|
2024-11-21 14:40 |
2020-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202298
|
6.7 |
MEDIUM
Local
|
huawei
|
taurus-an00b_firmware
|
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerabil…
|
CWE-20
Improper Input Validation
|
CVE-2020-9105
|
2024-11-21 14:40 |
2020-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202299
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.2.0 to 1.11.4, the NiFi UI and API were protected by mandating TLS v1.2, as well as listening connections established by processors like ListenHTTP, HandleHttpRequest, etc. However i…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-9491
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202300
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
In Apache NiFi 1.0.0 to 1.11.4, the NiFi download token (one-time password) mechanism used a fixed cache size and did not authenticate a request to create a download token, only when attempting to us…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9487
|
2024-11-21 14:40 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|