Huawei Campusinsight vulnerabilities

3 known vulnerabilities affecting huawei/campusinsight.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-22293HIGHCVSS 7.5vv100r019c102021-02-06
CVE-2021-22293 [HIGH] CWE-444 CVE-2021-22293: Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers c Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1RC2, 8.0.RC2. Affected product versions include: Tauru
nvd
CVE-2020-1862LOWCVSS 3.3vv100r019c002020-03-20
CVE-2020-1862 [LOW] CWE-415 CVE-2020-1862: There is a double free vulnerability in some Huawei products. A local attacker with low privilege ma There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some service abnormal. Affected product versions include:CampusInsight versions V100R019C00;ManageOne versions 6.5.RC2.B050.
nvd
CVE-2019-5278MEDIUMCVSS 6.5vv100r019c002019-12-13
CVE-2019-5278 [MEDIUM] CWE-125 CVE-2019-5278: There is an out-of-bounds read vulnerability in the Advanced Packages feature of the Gauss100 OLTP d There is an out-of-bounds read vulnerability in the Advanced Packages feature of the Gauss100 OLTP database in CampusInsight before V100R019C00SPC200. Attackers who gain the specific permission can use this vulnerability by sending elaborate SQL statements to the database. Successful exploit of this vulnerability may cause the database to crash.
nvd