Huawei S12700 Firmware vulnerabilities
29 known vulnerabilities affecting huawei/s12700_firmware.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH14MEDIUM14LOW1
Vulnerabilities
Page 1 of 2
CVE-2017-17300P3HIGHCVSS 7.5vv200r008c00vv200r009c002018-02-15
CVE-2017-17300 [HIGH] CWE-20 CVE-2017-17300: Huawei S12700 V200R008C00, V200R009C00, S5700 V200R007C00, V200R008C00, V200R009C00, S6700 V200R008C
Huawei S12700 V200R008C00, V200R009C00, S5700 V200R007C00, V200R008C00, V200R009C00, S6700 V200R008C00, V200R009C00, S7700 V200R008C00, V200R009C00, S9700 V200R008C00, V200R009C00 have a numeric errors vulnerability. An unauthenticated, remote attacker may send specific TCP messages with keychain authentication option to the affected products. Due to t
nvd
CVE-2021-22377P3HIGHCVSS 7.2vv200r019c00spc5002021-06-22
CVE-2021-22377 [HIGH] CWE-20 CVE-2021-22377: There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S57
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal servic
nvd
CVE-2016-4087P3HIGHCVSS 8.1vv200r005c00spc3002016-05-23
CVE-2016-4087 [HIGH] CWE-20 CVE-2016-4087: Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software befor
Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enabled, allows remote attackers to cause a denial of service or execute arbitrary code via crafted DNS packets.
nvd
CVE-2019-5285P3HIGHCVSS 7.5vv200r005c00vv200r006c00+6 more2019-06-04
CVE-2019-5285 [HIGH] CWE-20 CVE-2019-5285: Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send
Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send crafted packets to the affected device to exploit this vulnerability. Due to insufficient verification of the packets, successful exploitation may cause the device reboot and denial of service (DoS) condition. (Vulnerability ID: HWPSIRT-2019-03109)
nvd
CVE-2016-8786P3HIGHCVSS 7.5vv200r005c00vv200r006c00+2 more2018-03-09
CVE-2016-8786 [HIGH] CWE-20 CVE-2016-8786: Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V2
Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V200R008C00, S6700 V200R008C00, S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00 have a denial of service (DoS) vu
nvd
CVE-2016-2404P3HIGHCVSS 7.5vv200r005c00spc500vv200r006c002017-04-02
CVE-2016-2404 [HIGH] CWE-264 CVE-2016-2404: Huawei switches S5700, S6700, S7700, S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R
Huawei switches S5700, S6700, S7700, S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300, V200R005C00SPC500, V200R006C00; S12700 with software V200R005C00SPC500, V200R006C00; ACU2 with software V200R005C00SPC500, V200R006C00 have a permission control vulnerability. If a switch enables Authentication, Authorization, and Accounting
nvd
CVE-2021-37129P3HIGHCVSS 7.5vv200r010c00spc600vv200r011c10spc500+7 more2021-10-27
CVE-2021-37129 [HIGH] CWE-787 CVE-2021-37129: There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused b
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005
nvd
CVE-2016-8797P3HIGHCVSS 7.5vv200r007c00vv200r008c002017-04-02
CVE-2016-8797 [HIGH] CWE-399 CVE-2016-8797: Huawei AR3200 with software V200R007C00, V200R005C32, V200R005C20; S12700 with software V200R008C00,
Huawei AR3200 with software V200R007C00, V200R005C32, V200R005C20; S12700 with software V200R008C00, V200R007C00; S5300 with software V200R008C00, V200R007C00, V200R006C00; S5700 with software V200R008C00, V200R007C00, V200R006C00; S6300 with software V200R008C00, V200R007C00; S6700 with software V200R008C00, V200R007C00; S7700 with software V200R008C00
nvd
CVE-2017-8147P3HIGHCVSS 7.5vv200r005c00vv200r006c00+2 more2017-11-22
CVE-2017-8147 [HIGH] CWE-20 CVE-2017-8147: AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C
AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with software V100R003C00, V100R005C00, V100R005
nvd
CVE-2019-19397P3HIGHCVSS 7.5vv200r007c00vv200r007c01+5 more2019-12-13
CVE-2019-19397 [HIGH] CVE-2019-19397: There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algo
There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks.
nvd
CVE-2016-8773P3HIGHCVSS 7.5vv200r007c00vv200r007c01+2 more2017-04-02
CVE-2016-8773 [HIGH] CWE-20 CVE-2016-8773: Huawei S5300 with software V200R003C00, V200R007C00, V200R008C00, V200R009C00; S5700 with software V
Huawei S5300 with software V200R003C00, V200R007C00, V200R008C00, V200R009C00; S5700 with software V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C03, V200R007C00, V200R008C00, V200R009C00; S6300 with software V200R003C00, V200R005C00, V200R008C00, V200R009C00; S6700 with software V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C
nvd
CVE-2021-22357P3HIGHCVSS 7.5vv200r013c00spc500vv200r019c00spc5002021-08-23
CVE-2021-22357 [HIGH] CWE-20 CVE-2021-22357: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due to validating inputs insufficiently. Attackers can exploit this vulnerability by sending specific messages to affected module. This can cause denial of service. Affected product versions include: S12700 V200R013C00SPC500, V200R019C00SPC500; S5
nvd
CVE-2015-3913P4HIGHCVSS 7.5vv200r005c00spc300vv200r006c00spc500+1 more2017-06-08
CVE-2015-3913 [HIGH] CWE-20 CVE-2015-3913: The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denia
The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message.
nvd
CVE-2016-6518P4HIGHCVSS 7.5vv200r005c00vv200r006c00+1 more2016-09-26
CVE-2016-6518 [HIGH] CWE-399 CVE-2016-6518: Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote att
Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malformed packets.
nvd
CVE-2017-17250P4MEDIUMCVSS 6.5vv200r007c00vv200r007c01+1 more2018-03-09
CVE-2017-17250 [MEDIUM] CWE-787 CVE-2017-17250: Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V20
Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-boun
nvd
CVE-2020-1866P4MEDIUMCVSS 6.5vv200r008c002021-01-13
CVE-2020-1866 [MEDIUM] CWE-125 CVE-2020-1866: There is an out-of-bounds read vulnerability in several products. The software reads data past the e
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700
nvd
CVE-2021-22321P4MEDIUMCVSS 5.3vv200r007c01vv200r007c01b102+6 more2021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2021-22329P4MEDIUMCVSS 4.9vv200r007c01vv200r007c01b102+5 more2021-06-29
CVE-2021-22329 [MEDIUM] CVE-2021-22329: There has a license management vulnerability in some Huawei products. An attacker with high privileg
There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S1
nvd
CVE-2015-8085P4MEDIUMCVSS 4.9vv200r005c00vv200r006c002016-10-03
CVE-2015-8085 [MEDIUM] CWE-326 CVE-2015-8085: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrator
nvd
CVE-2015-8086P4MEDIUMCVSS 4.9vv200r005c00vv200r006c002016-10-03
CVE-2015-8086 [MEDIUM] CWE-326 CVE-2015-8086: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrato
nvd
1 / 2Next →