Huawei Ips Module Firmware vulnerabilities
52 known vulnerabilities affecting huawei/ips_module_firmware.
Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH19MEDIUM28LOW3
Vulnerabilities
Page 1 of 3
CVE-2020-1822MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-28
CVE-2020-1822 [LOW] CVE-2020-1822: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1820MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-28
CVE-2020-1820 [LOW] CVE-2020-1820: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1823MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-28
CVE-2020-1823 [LOW] CVE-2020-1823: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1821MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-28
CVE-2020-1821 [LOW] CVE-2020-1821: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1824MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-28
CVE-2020-1824 [LOW] CVE-2020-1824: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1818MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-27
CVE-2020-1818 [LOW] CWE-125 CVE-2020-1818: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerabil
nvd
CVE-2020-1819MEDIUMCVSS 5.3vv500r001c30vv500r001c60+1 more2024-12-27
CVE-2020-1819 [LOW] CVE-2020-1819: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open
There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2021-22356MEDIUMCVSS 5.9vv500r005c00spc100vv500r005c00spc2002021-11-23
CVE-2021-22356 [MEDIUM] CWE-327 CVE-2021-22356: There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used i
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; N
nvd
CVE-2021-37129HIGHCVSS 7.5vv500r005c00vv500r005c202021-10-27
CVE-2021-37129 [HIGH] CWE-787 CVE-2021-37129: There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused b
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005
nvd
CVE-2021-22341MEDIUMCVSS 4.9vv500r005c00spc100vv500r005c00spc2002021-06-29
CVE-2021-22341 [MEDIUM] CWE-401 CVE-2021-22341: There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a
There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R005C00SPC200;NGFW Module V500R005C00SPC100,V500R005C00
nvd
CVE-2021-22342MEDIUMCVSS 4.9vv500r005c00vv500r005c10+1 more2021-06-22
CVE-2021-22342 [MEDIUM] CVE-2021-22342: There is an information leak vulnerability in Huawei products. A module does not deal with specific
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V50
nvd
CVE-2021-22312MEDIUMCVSS 6.5vv500r005c00spc100vv500r005c00spc2002021-04-08
CVE-2021-22312 [MEDIUM] CWE-401 CVE-2021-22312: There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may e
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Sec
nvd
CVE-2021-22320HIGHCVSS 7.5vv500r005c00spc100vv500r005c00spc200+1 more2021-03-22
CVE-2021-22320 [HIGH] CVE-2021-22320: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace
nvd
CVE-2020-9101MEDIUMCVSS 6.5vv500r005c00vv500r005c102020-07-18
CVE-2020-9101 [MEDIUM] CWE-787 CVE-2020-9101: There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts m
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V
nvd
CVE-2019-19416HIGHCVSS 7.5vv100r001c10vv100r001c20+5 more2020-07-08
CVE-2019-19416 [HIGH] CWE-20 CVE-2019-19416: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19417HIGHCVSS 7.5vv100r001c10vv100r001c20+5 more2020-07-08
CVE-2019-19417 [HIGH] CWE-20 CVE-2019-19417: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19415HIGHCVSS 7.5vv100r001c10vv100r001c20+5 more2020-07-08
CVE-2019-19415 [HIGH] CWE-20 CVE-2019-19415: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2020-9099CRITICALCVSS 9.8vv500r001c00vv500r001c20+7 more2020-06-08
CVE-2020-9099 [CRITICAL] CWE-287 CVE-2020-9099: Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication v
nvd
CVE-2019-5304HIGHCVSS 7.5vv500r001c20vv500r001c302020-01-03
CVE-2019-5304 [HIGH] CWE-120 CVE-2019-5304: Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could se
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.
nvd
CVE-2017-17256HIGHCVSS 7.5vv100r001c10spc200vv100r001c30+4 more2018-04-24
CVE-2017-17256 [HIGH] CWE-772 CVE-2017-17256: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
1 / 3Next →