Huawei Dp300 Firmware vulnerabilities
87 known vulnerabilities affecting huawei/dp300_firmware.
Total CVEs
87
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH16MEDIUM58LOW12
Vulnerabilities
Page 2 of 5
CVE-2017-17146HIGHCVSS 7.8≤ v500r002c002018-03-09
CVE-2017-17146 [HIGH] CWE-119 CVE-2017-17146: Huawei DP300 V500R002C00 have a buffer overflow vulnerability due to the lack of validation. An auth
Huawei DP300 V500R002C00 have a buffer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks or remote code execution on the device.
nvd
CVE-2017-15314MEDIUMCVSS 5.5vv500r002c002018-03-09
CVE-2017-15314 [MEDIUM] CWE-772 CVE-2017-15314: Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10S
Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00
nvd
CVE-2017-17150MEDIUMCVSS 5.5vv500r002c002018-03-09
CVE-2017-17150 [MEDIUM] CWE-835 CVE-2017-17150: Timergrp module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R
Timergrp module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an DoS vulnerability due to insufficient validation of the parameter. An authenticated local attacker may call a special
nvd
CVE-2017-15323MEDIUMCVSS 5.5vv500r002c002018-03-09
CVE-2017-15323 [MEDIUM] CWE-400 CVE-2017-15323: Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C
Huawei DP300 V500R002C00, NIP6600 V500R001C00, V500R001C20, V500R001C30, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, TE60 V100R001C01, V100R001C10, V100R003C00, V500R002C00, V600R006C00, TP3106 V100R001C06, V100R002C00, VP9660 V200R001C02, V200R001C30, V500R002C00, V500R002C10, ViewPoint 8660 V100R008C03, ViewPoint 9030 V100R011C02, V10
nvd
CVE-2017-17199MEDIUMCVSS 5.9vv500r002c002018-03-09
CVE-2017-17199 [MEDIUM] CWE-125 CVE-2017-17199: Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability due to the improper processing of malformed H323 messages. A remote attacker that controls a server cou
nvd
CVE-2017-17216MEDIUMCVSS 5.9vv500r002c002018-03-09
CVE-2017-17216 [MEDIUM] CWE-125 CVE-2017-17216: Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006
Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability. An unauthenticated, remote attacker crafts malformed pa
nvd
CVE-2017-17303MEDIUMCVSS 4.9vv500r002c00vv500r002c00b010+15 more2018-03-09
CVE-2017-17303 [MEDIUM] CWE-200 CVE-2017-17303: Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R0
Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; RP200 V500R002C00SPC200; V600R006C0
nvd
CVE-2017-17217MEDIUMCVSS 5.9vv500r002c002018-03-09
CVE-2017-17217 [MEDIUM] CWE-787 CVE-2017-17217: Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006
Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds write vulnerability. An unauthenticated, remote attacker crafts malformed pa
nvd
CVE-2017-17304MEDIUMCVSS 6.5vv500r002c00vv500r002c00b010+15 more2018-03-09
CVE-2017-17304 [MEDIUM] CWE-20 CVE-2017-17304: The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insu
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnor
nvd
CVE-2017-17167MEDIUMCVSS 5.9vv500r002c002018-03-09
CVE-2017-17167 [MEDIUM] CWE-327 CVE-2017-17167: Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02; V100R011C03 have a use of
Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02; V100R011C03 have a use of a broken or risky cryptographic algorithm vulnerability. The software uses risky cryptographic algorithm in SSL. This is dangerous because a remote unauthenticated attacker could use well-known techniques to break the algorithm. Successful exploit coul
nvd
CVE-2017-17218MEDIUMCVSS 5.3vv500r002c002018-03-09
CVE-2017-17218 [MEDIUM] CWE-125 CVE-2017-17218: SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability. An unauthenticated, remote attacker crafts malformed packets with specific parameter to
nvd
CVE-2017-17169MEDIUMCVSS 6.5vv500r002c00vv500r002c00b010+15 more2018-03-09
CVE-2017-17169 [MEDIUM] CWE-20 CVE-2017-17169: The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insu
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnor
nvd
CVE-2017-17168MEDIUMCVSS 6.5vv500r002c00vv500r002c00b010+15 more2018-03-09
CVE-2017-17168 [MEDIUM] CWE-20 CVE-2017-17168: The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insu
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnor
nvd
CVE-2017-17219MEDIUMCVSS 5.3vv500r002c002018-03-09
CVE-2017-17219 [MEDIUM] CWE-20 CVE-2017-17219: SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific paramete
nvd
CVE-2017-17148MEDIUMCVSS 5.5≤ v500r002c002018-03-09
CVE-2017-17148 [MEDIUM] CWE-20 CVE-2017-17148: Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is c
Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is called. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks.
nvd
CVE-2017-17220MEDIUMCVSS 5.3vv500r002c002018-03-09
CVE-2017-17220 [MEDIUM] CWE-125 CVE-2017-17220: SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002
SCCPX module in Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an invalid memory access vulnerabilities. An unauthenticated, remote attacker crafts malformed packets with specific paramet
nvd
CVE-2017-17281MEDIUMCVSS 4.3vv500r002c002018-03-09
CVE-2017-17281 [MEDIUM] CWE-125 CVE-2017-17281: SFTP module in Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C
SFTP module in Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds read vulnerability. A remote, authenticated attacker could exploit this vulnerability by sending specially crafted messag
nvd
CVE-2017-17170MEDIUMCVSS 6.5vv500r002c00vv500r002c00b010+15 more2018-03-09
CVE-2017-17170 [MEDIUM] CWE-20 CVE-2017-17170: The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insu
The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit could allow the attacker to tamper with business and make the system abnor
nvd
CVE-2017-17147MEDIUMCVSS 5.5≤ v500r002c002018-03-09
CVE-2017-17147 [MEDIUM] CWE-190 CVE-2017-17147: Huawei DP300 V500R002C00 have an integer overflow vulnerability due to the lack of validation. An au
Huawei DP300 V500R002C00 have an integer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks.
nvd
CVE-2017-17200MEDIUMCVSS 5.9vv500r002c002018-03-09
CVE-2017-17200 [MEDIUM] CWE-125 CVE-2017-17200: Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability due to the improper processing of malformed H323 messages. A remote attacker that controls a server cou
nvd