CVE-2014-9137
published 2017-04-02CVE-2014-9137: Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with…
PriorityP344high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
32.6th percentile
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | fusionmanager | — | — |
| huawei | fusionmanager | — | — |
| huawei | usg2100_firmware | <= v300r001c00spc900 | — |
| huawei | usg2200_firmware | <= v300r001c00spc900 | — |
| huawei | usg5100_firmware | <= v300r001c00spc900 | — |
| huawei | usg5500_firmware | <= v300r001c00spc900 | — |
| huawei | usg9500_firmware | <= v200r001c01spc800 | — |
| huawei | usg9500_firmware | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8753-fcrc-w2vr: Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG220
ghsa_unreviewed·2022-05-17
CVE-2014-9137 [HIGH] CWE-352 GHSA-8753-fcrc-w2vr: Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG220
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
Red Hat
kernel: regulator: da9121: Fix uninit-value in da9121_assign_chip_model()
vendor_redhat·2025-02-26·CVSS 5.5
CVE-2022-49507 [MEDIUM] CWE-908 kernel: regulator: da9121: Fix uninit-value in da9121_assign_chip_model()
kernel: regulator: da9121: Fix uninit-value in da9121_assign_chip_model()
In the Linux kernel, the following vulnerability has been resolved:
regulator: da9121: Fix uninit-value in da9121_assign_chip_model()
KASAN report slab-out-of-bounds in __regmap_init as follows:
BUG: KASAN: slab-out-of-bounds in __regmap_init drivers/base/regmap/regmap.c:841
Read of size 1 at addr ffff88803678cdf1 by task xrun/9137
CPU: 0 PID: 9137 Comm: xrun Tainted: G W 5.18.0-rc2
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014
Call Trace:
dump_stack_lvl+0xe8/0x15a lib/dump_stack.c:88
print_report.cold+0xcd/0x69b mm/kasan/report.c:313
kasan_report+0x8e/0xc0 mm/kasan/report.c:491
__regmap_init+0x4540/0x4ba0 drivers/base/regmap/regmap.c:841
__devm_regmap_init+0x7a/0x100 driv
No detection rules found.
No public exploits indexed.
2017-04-02
Published