cbcvebase.

Huawei Nip6800 Firmware vulnerabilities

59 known vulnerabilities affecting huawei/nip6800_firmware.

Total CVEs
59
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH22MEDIUM33LOW3

Vulnerabilities

Page 3 of 3
CVE-2020-1823P4MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1823 [MEDIUM] CVE-2020-1823: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability I
nvd
CVE-2020-1821P4MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-28
CVE-2020-1821 [MEDIUM] CVE-2020-1821: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability I
nvd
CVE-2020-1818P4MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-27
CVE-2020-1818 [MEDIUM] CWE-125 CVE-2020-1818: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnera
nvd
CVE-2020-1819P4MEDIUMCVSS 5.3vv500r001c60vv500r005c002024-12-27
CVE-2020-1819 [MEDIUM] CVE-2020-1819: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability I
nvd
CVE-2020-9201P4MEDIUMCVSS 6.5vv500r001c30vv500r001c60spc500+1 more2020-12-24
CVE-2020-9201 [MEDIUM] CWE-125 CVE-2020-9201: There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9 There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.
nvd
CVE-2020-1814P4MEDIUMCVSS 5.3vv500r001c30vv500r001c60spc500+1 more2020-02-18
CVE-2020-1814 [MEDIUM] CWE-119 CVE-2020-1814: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability. An authenticated attacker may do some special operations in the affected products in some special scenarios to exploi
nvd
CVE-2020-1830P4MEDIUMCVSS 5.3vv500r001c30vv500r001c60spc500+1 more2020-02-18
CVE-2020-1830 [MEDIUM] CWE-125 CVE-2020-1830: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a vulnerability that a memory management error exists when IPSec Module handing a specific message. This causes 1 byte out-of-bound read, compromising normal servi
nvd
CVE-2020-1857P4MEDIUMCVSS 5.5vv500r001c30vv500r001c60spc500+1 more2020-02-17
CVE-2020-1857 [MEDIUM] CVE-2020-1857: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. Due to improper processing of some data, a local authenticated attacker can exploit this vulnerability through a seri
nvd
CVE-2019-5258P4MEDIUMCVSS 5.5vv500r001c50vv500r001c50pwe+2 more2019-12-13
CVE-2019-5258 [MEDIUM] CWE-120 CVE-2019-5258: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a buffer overflow vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port o
nvd
CVE-2020-1874P4MEDIUMCVSS 5.5vv500r001c30vv500r001c60spc500+1 more2020-02-28
CVE-2020-1874 [MEDIUM] CWE-824 CVE-2020-1874: NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SP NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot.
nvd
CVE-2020-1875P4MEDIUMCVSS 5.5vv500r001c30vv500r001c60spc5002020-02-28
CVE-2020-1875 [MEDIUM] CWE-824 CVE-2020-1875: NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SP NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when an abnormal condition occurs in certain operation. Successful exploit could cause certain process reboot. Affected product versions include:NIP6800 ver
nvd
CVE-2019-5255P4MEDIUMCVSS 5.5vv500r001c50vv500r001c50pwe+2 more2019-12-13
CVE-2019-5255 [MEDIUM] CWE-125 CVE-2019-5255: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a DoS vulnerability. An attacker may send crafted messages from a FTP client to exploit this vulnerability. Due to insufficient
nvd
CVE-2019-5257P4MEDIUMCVSS 5.5vv500r001c50vv500r001c50pwe+2 more2019-12-13
CVE-2019-5257 [MEDIUM] CWE-120 CVE-2019-5257: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace) have a resource management vulnerability. An attacker who logs in to the board may send crafted messages from the internal network.
nvd
CVE-2020-1883P4MEDIUMCVSS 4.9vv500r001c60spc500vV500R001C60SPC5002020-06-05
CVE-2020-1883 [MEDIUM] CWE-401 CVE-2020-1883: Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.
nvd
CVE-2019-5256P4MEDIUMCVSS 5.5vv500r001c50vv500r001c50pwe+2 more2019-12-13
CVE-2019-5256 [MEDIUM] CWE-476 CVE-2019-5256: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a null pointer dereference vulnerability. The system dereferences a pointer that it expects to be valid, but is NULL. A local at
nvd
CVE-2020-1877P4MEDIUMCVSS 4.4vv500r001c30vv500r001c60spc500+1 more2020-02-28
CVE-2020-1877 [MEDIUM] CWE-824 CVE-2020-1877: NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful exploit could cause certain process reboot.
nvd
CVE-2017-15337P4LOWCVSS 3.7vv500r001c502018-02-15
CVE-2017-15337 [LOW] CWE-119 CVE-2017-15337: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-15338P4LOWCVSS 3.7vv500r001c502018-02-15
CVE-2017-15338 [LOW] CWE-119 CVE-2017-15338: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-15339P4LOWCVSS 3.7vv500r001c502018-02-15
CVE-2017-15339 [LOW] CWE-119 CVE-2017-15339: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
Huawei Nip6800 Firmware vulnerabilities | cvebase