Huawei Nip6800 Firmware vulnerabilities

59 known vulnerabilities affecting huawei/nip6800_firmware.

Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH22MEDIUM33LOW3

Vulnerabilities

Page 1 of 3
CVE-2020-1822MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1822 [LOW] CVE-2020-1822: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1820MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1820 [LOW] CVE-2020-1820: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1823MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1823 [LOW] CVE-2020-1823: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1821MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1821 [LOW] CVE-2020-1821: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1824MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1824 [LOW] CVE-2020-1824: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2020-1818MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-27
CVE-2020-1818 [LOW] CWE-125 CVE-2020-1818: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerabil
nvd
CVE-2020-1819MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-27
CVE-2020-1819 [LOW] CVE-2020-1819: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID:
nvd
CVE-2021-22312MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+3 more2021-04-08
CVE-2021-22312 [MEDIUM] CWE-401 CVE-2021-22312: There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may e There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Sec
nvd
CVE-2020-9213HIGHCVSS 7.5vv500r001c60vv500r005c002021-03-22
CVE-2020-9213 [HIGH] CVE-2020-9213: There is a denial of service vulnerability in some huawei products. In specific scenarios, due to th There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500, Se
nvd
CVE-2021-22320HIGHCVSS 7.5vv500r001c60spc500vv500r005c00spc100+3 more2021-03-22
CVE-2021-22320 [HIGH] CVE-2021-22320: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace
nvd
CVE-2021-22321MEDIUMCVSS 5.3vv500r001c602021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2020-1866MEDIUMCVSS 6.5vv500r001c30vv500r001c60spc500+1 more2021-01-13
CVE-2020-1866 [MEDIUM] CWE-125 CVE-2020-1866: There is an out-of-bounds read vulnerability in several products. The software reads data past the e There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700
nvd
CVE-2020-9201MEDIUMCVSS 6.5vv500r001c30vv500r001c60spc500+1 more2020-12-24
CVE-2020-9201 [MEDIUM] CWE-125 CVE-2020-9201: There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9 There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.
nvd
CVE-2019-19416HIGHCVSS 7.5vv500r001c30vv500r001c502020-07-08
CVE-2019-19416 [HIGH] CWE-20 CVE-2019-19416: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19417HIGHCVSS 7.5vv500r001c30vv500r001c502020-07-08
CVE-2019-19417 [HIGH] CWE-20 CVE-2019-19417: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19415HIGHCVSS 7.5vv500r001c30vv500r001c502020-07-08
CVE-2019-19415 [HIGH] CWE-20 CVE-2019-19415: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2020-9099CRITICALCVSS 9.8vv500r001c60vv500r001c80+3 more2020-06-08
CVE-2020-9099 [CRITICAL] CWE-287 CVE-2020-9099: Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication v
nvd
CVE-2020-1883MEDIUMCVSS 4.9vv500r001c60spc5002020-06-05
CVE-2020-1883 [MEDIUM] CWE-401 CVE-2020-1883: Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.
nvd
CVE-2020-1873HIGHCVSS 7.5vv500r001c30vv500r001c60spc500+1 more2020-02-28
CVE-2020-1873 [HIGH] CWE-125 CVE-2020-1873: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005 NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the
nvd
CVE-2020-1860HIGHCVSS 7.5vv500r001c30vv500r001c60+1 more2020-02-28
CVE-2020-1860 [HIGH] CVE-2020-1860: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005 NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be bypassed, and attackers can directly access the
nvd