Lucene search

K

HUAWEI Security Vulnerabilities

cve
cve

CVE-2021-22293

Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1...

7.5CVSS

7.3AI Score

0.002EPSS

2021-02-06 03:15 AM
70
3
cve
cve

CVE-2021-22294

A component API of the HarmonyOS 2.0 has a permission bypass vulnerability. Local attackers may exploit this vulnerability to issue commands repeatedly, exhausting system service resources.

3.3CVSS

4.3AI Score

0.0004EPSS

2021-03-02 07:15 PM
20
4
cve
cve

CVE-2021-22295

A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

5.5CVSS

5.4AI Score

0.0004EPSS

2021-08-06 01:15 PM
24
2
cve
cve

CVE-2021-22296

A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file system to the target device, causing DoS of the file system.

5.5CVSS

5.5AI Score

0.0004EPSS

2021-03-02 07:15 PM
17
5
cve
cve

CVE-2021-22298

There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful exploit can cause service abnormal. Affected product versions include: ManageOne v...

6.5CVSS

7.1AI Score

0.001EPSS

2021-02-06 02:15 AM
78
10
cve
cve

CVE-2021-22299

There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne version...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-02-06 02:15 AM
63
2
cve
cve

CVE-2021-22300

There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have timeout exit mechanism. Temporary file contains sensitive information. This allows attackers to obtain information by inter-process access that requires other methods.

4.1CVSS

4.3AI Score

0.0004EPSS

2021-02-06 01:15 AM
67
2
cve
cve

CVE-2021-22301

Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulnerability. After obtaining the root permission, an attacker can exploit the vulnerability to cause buffer overflow.

6.7CVSS

6.7AI Score

0.0004EPSS

2021-02-06 12:15 AM
63
5
cve
cve

CVE-2021-22302

There is an out-of-bound read vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module does not verify the some input. Attackers can exploit this vulnerability by sending malicious input through specific app. This could cause out-of-bound, compromising normal service.

7.1CVSS

6.8AI Score

0.0004EPSS

2021-02-06 03:15 AM
64
3
cve
cve

CVE-2021-22303

There is a pointer double free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). There is a lack of muti-thread protection when a function is called. Attackers can exploit this vulnerability by performing malicious operation to cause pointer double free. This may lead to module crash, compromising...

3.3CVSS

4.2AI Score

0.001EPSS

2021-02-06 01:15 AM
66
2
cve
cve

CVE-2021-22304

There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compro...

3.3CVSS

4.2AI Score

0.0004EPSS

2021-02-06 03:15 AM
67
2
cve
cve

CVE-2021-22305

There is a buffer overflow vulnerability in Mate 30 10.1.0.126(C00E125R5P3). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause buffer overflow, compromising normal service...

3.3CVSS

4.6AI Score

0.0004EPSS

2021-02-06 03:15 AM
69
6
cve
cve

CVE-2021-22306

There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input when dealing with messages. Attackers can exploit this vulnerability by sending malicious input through specific module. This could cause out-of-bound, compromising normal service...

4.6CVSS

4.7AI Score

0.001EPSS

2021-02-06 01:15 AM
70
2
cve
cve

CVE-2021-22307

There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the modules that should be protected. Local attackers can exploit this vulnerability to affect the integrity of certain module.

5.5CVSS

5.4AI Score

0.0004EPSS

2021-02-06 12:15 AM
58
6
cve
cve

CVE-2021-22308

There is a Business Logic Errors vulnerability in Huawei Smartphone. The malicious apps installed on the device can keep taking screenshots in the background. This issue does not cause system errors, but may cause personal information leakage.

3.3CVSS

4AI Score

0.0004EPSS

2021-06-03 04:15 PM
30
2
cve
cve

CVE-2021-22309

There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C...

7.5CVSS

7.2AI Score

0.002EPSS

2021-03-22 06:15 PM
35
cve
cve

CVE-2021-22310

There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include:...

4.4CVSS

4.5AI Score

0.0004EPSS

2021-03-22 07:15 PM
24
cve
cve

CVE-2021-22311

There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected product versions include: ...

7.2CVSS

6.8AI Score

0.001EPSS

2021-03-22 07:15 PM
18
3
cve
cve

CVE-2021-22312

There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product i...

6.5CVSS

6.4AI Score

0.001EPSS

2021-04-08 07:15 PM
42
4
cve
cve

CVE-2021-22313

There is a Security Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

7.5CVSS

7.5AI Score

0.002EPSS

2021-06-03 04:15 PM
30
4
cve
cve

CVE-2021-22314

There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.

7.8CVSS

7.5AI Score

0.0004EPSS

2021-03-22 08:15 PM
23
2
cve
cve

CVE-2021-22316

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Attackers with physical access to the device can thereby exploit this vulnerability. A successful exploitation of this vulnerability can compromise the device's data security and functional availability.

6.8CVSS

6.5AI Score

0.001EPSS

2021-06-03 04:15 PM
30
2
cve
cve

CVE-2021-22317

There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

7.5CVSS

7.4AI Score

0.002EPSS

2021-06-03 04:15 PM
25
6
cve
cve

CVE-2021-22318

A component of the HarmonyOS 2.0 has a Null Pointer Dereference Vulnerability. Local attackers may exploit this vulnerability to cause system denial of service.

5.5CVSS

5.3AI Score

0.0004EPSS

2021-07-14 11:15 AM
21
5
cve
cve

CVE-2021-22319

There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause integer overflows.

7.5CVSS

7.5AI Score

0.001EPSS

2022-02-25 07:15 PM
50
cve
cve

CVE-2021-22320

There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Modul...

7.5CVSS

7.3AI Score

0.001EPSS

2021-03-22 07:15 PM
45
cve
cve

CVE-2021-22321

There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include s...

5.3CVSS

5.3AI Score

0.001EPSS

2021-03-22 08:15 PM
36
2
cve
cve

CVE-2021-22322

There is a Missing Authentication for Critical Function vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

7.5CVSS

7.5AI Score

0.002EPSS

2021-06-03 04:15 PM
31
6
cve
cve

CVE-2021-22323

There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

9.8CVSS

9.6AI Score

0.002EPSS

2021-06-30 03:15 PM
32
cve
cve

CVE-2021-22324

There is a Credentials Management Errors vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may impair data confidentiality.

7.5CVSS

7.5AI Score

0.002EPSS

2021-06-03 05:15 PM
30
6
cve
cve

CVE-2021-22325

There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may result in video streams being intercepted during transmission.

5.3CVSS

5.1AI Score

0.001EPSS

2021-06-03 05:15 PM
34
5
cve
cve

CVE-2021-22326

A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.

7.1CVSS

6.8AI Score

0.0004EPSS

2021-06-30 02:15 PM
23
cve
cve

CVE-2021-22327

There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions 10.0.0.186(C10E7R5P1), 10.0.0.186(C4...

6.5CVSS

6.5AI Score

0.001EPSS

2021-04-28 12:15 PM
20
3
cve
cve

CVE-2021-22328

There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft the specific packet. Successful exploit may cause some services abnormal. Affected product versions include:CloudEngine 12800 V200R005C00SPC8...

7.5CVSS

7.4AI Score

0.001EPSS

2021-08-23 08:15 PM
23
2
cve
cve

CVE-2021-22329

There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect i...

4.9CVSS

5AI Score

0.001EPSS

2021-06-29 08:15 PM
24
cve
cve

CVE-2021-22330

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input paramete...

6.5CVSS

6.5AI Score

0.001EPSS

2021-04-28 12:15 PM
21
2
cve
cve

CVE-2021-22331

There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service. Affected product ve...

7.5CVSS

7.6AI Score

0.001EPSS

2021-04-28 01:15 PM
21
3
cve
cve

CVE-2021-22332

There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and CloudEngine 12800. When a function is called, the same memory pointer is copied to two functional modules. Attackers can exploit this vulnerability by performing a malicious ope...

7.5CVSS

7.4AI Score

0.001EPSS

2021-04-28 01:15 PM
22
4
cve
cve

CVE-2021-22333

There is an Improper Validation of Array Index vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause code to execute, thus obtaining system permissions.

9.8CVSS

9.3AI Score

0.002EPSS

2021-06-03 08:15 PM
43
6
cve
cve

CVE-2021-22334

There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause app redirections.

7.4CVSS

7.4AI Score

0.001EPSS

2021-06-03 08:15 PM
44
8
cve
cve

CVE-2021-22335

There is a Memory Buffer Improper Operation Limit vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause exceptions in image processing.

7.8CVSS

7.6AI Score

0.0004EPSS

2021-06-03 08:15 PM
47
7
cve
cve

CVE-2021-22336

There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial of security services on a rooted device.

7.5CVSS

7.6AI Score

0.001EPSS

2021-06-03 05:15 PM
30
5
cve
cve

CVE-2021-22337

There is an Information Disclosure vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause leaking of user click data.

5.3CVSS

5.1AI Score

0.001EPSS

2021-06-03 08:15 PM
40
4
cve
cve

CVE-2021-22338

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.

5.3CVSS

5.3AI Score

0.001EPSS

2021-06-29 07:15 PM
19
2
cve
cve

CVE-2021-22339

There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal.

6.5CVSS

6.3AI Score

0.001EPSS

2021-05-20 08:15 PM
39
2
cve
cve

CVE-2021-22340

There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause...

4.1CVSS

4.3AI Score

0.0004EPSS

2021-06-29 07:15 PM
16
2
cve
cve

CVE-2021-22341

There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R0...

4.9CVSS

4.9AI Score

0.001EPSS

2021-06-29 08:15 PM
20
6
cve
cve

CVE-2021-22342

There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V5...

4.9CVSS

4.9AI Score

0.001EPSS

2021-06-22 07:15 PM
37
5
cve
cve

CVE-2021-22343

There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.

9.1CVSS

9.1AI Score

0.001EPSS

2021-07-01 12:15 PM
25
4
cve
cve

CVE-2021-22344

There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.

5.3CVSS

5.3AI Score

0.001EPSS

2021-07-01 12:15 PM
19
4
Total number of security vulnerabilities1850