cbcvebase.

Huawei S5700 Firmware vulnerabilities

44 known vulnerabilities affecting huawei/s5700_firmware.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH23MEDIUM20LOW1

Vulnerabilities

Page 2 of 3
CVE-2014-4706P4HIGHCVSS 7.5vv200r001c00spc300vv200r003c00spc3002017-04-02
CVE-2014-4706 [HIGH] CWE-119 CVE-2014-4706: Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C00SPC300,V200R003C00SPC300,V200R003C00SPC500; S2350 with software V200R003C00SPC300; S2750 with software V200R003C00SPC300; S5300 with software V200R001C00SP
nvd
CVE-2016-3678P4HIGHCVSS 7.5vv200r003c00spc5002016-04-11
CVE-2016-3678 [HIGH] CWE-20 CVE-2016-3678: Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 al Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service (switch restart) via crafted traffic.
nvd
CVE-2016-6518P4HIGHCVSS 7.5vv200r001c00vv200r001c01+6 more2016-09-26
CVE-2016-6518 [HIGH] CWE-399 CVE-2016-6518: Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote att Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malformed packets.
nvd
CVE-2017-17250P4MEDIUMCVSS 6.5vv200r007c00vv200r008c002018-03-09
CVE-2017-17250 [MEDIUM] CWE-787 CVE-2017-17250: Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V20 Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-boun
nvd
CVE-2019-5290P4MEDIUMCVSS 6.5vv200r005c00spc500vv200r005c02+7 more2019-12-13
CVE-2019-5290 [MEDIUM] CVE-2019-5290: Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed properly, the vulnerability can be exploited to cause the device to be abnormal.
nvd
CVE-2014-5394P4MEDIUMCVSS 5.9vv200r001c00spc300vv200r002c00spc300+1 more2018-01-08
CVE-2014-5394 [MEDIUM] CWE-200 CVE-2014-5394: Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
nvd
CVE-2020-1866P4MEDIUMCVSS 6.5vv200r008c002021-01-13
CVE-2020-1866 [MEDIUM] CWE-125 CVE-2020-1866: There is an out-of-bounds read vulnerability in several products. The software reads data past the e There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700
nvd
CVE-2021-22321P4MEDIUMCVSS 5.3vv200r008c00vv200r010c00+5 more2021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2021-22329P4MEDIUMCVSS 4.9vv200r008c00vv200r010c00spc300+4 more2021-06-29
CVE-2021-22329 [MEDIUM] CVE-2021-22329: There has a license management vulnerability in some Huawei products. An attacker with high privileg There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S1
nvd
CVE-2020-1810P4MEDIUMCVSS 5.3vv200r005c00spc500vv200r005c03+5 more2020-01-09
CVE-2020-1810 [MEDIUM] CWE-327 CVE-2020-1810: There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA a There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.
nvd
CVE-2019-5258P4MEDIUMCVSS 5.5vv200r005c032019-12-13
CVE-2019-5258 [MEDIUM] CWE-120 CVE-2019-5258: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a buffer overflow vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port o
nvd
CVE-2015-8085P4MEDIUMCVSS 4.9vv200r001c00vv200r002c00+3 more2016-10-03
CVE-2015-8085 [MEDIUM] CWE-326 CVE-2015-8085: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrator
nvd
CVE-2015-8086P4MEDIUMCVSS 4.9vv200r001c00vv200r002c00+3 more2016-10-03
CVE-2015-8086 [MEDIUM] CWE-326 CVE-2015-8086: Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrato
nvd
CVE-2019-5255P4MEDIUMCVSS 5.5vv200r005c032019-12-13
CVE-2019-5255 [MEDIUM] CWE-125 CVE-2019-5255: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a DoS vulnerability. An attacker may send crafted messages from a FTP client to exploit this vulnerability. Due to insufficient
nvd
CVE-2019-5257P4MEDIUMCVSS 5.5vv200r005c032019-12-13
CVE-2019-5257 [MEDIUM] CWE-120 CVE-2019-5257: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace) have a resource management vulnerability. An attacker who logs in to the board may send crafted messages from the internal network.
nvd
CVE-2017-17138P4MEDIUMCVSS 5.5vv200r006c00vv200r007c00+3 more2018-03-05
CVE-2017-17138 [MEDIUM] CWE-20 CVE-2017-17138: PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10; V200R007
nvd
CVE-2017-17136P4MEDIUMCVSS 5.5vv200r006c00vv200r007c00+3 more2018-03-05
CVE-2017-17136 [MEDIUM] CWE-119 CVE-2017-17136: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2019-5256P4MEDIUMCVSS 5.5vv200r005c032019-12-13
CVE-2019-5256 [MEDIUM] CWE-476 CVE-2019-5256: Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a null pointer dereference vulnerability. The system dereferences a pointer that it expects to be valid, but is NULL. A local at
nvd
CVE-2017-17137P4MEDIUMCVSS 5.5vv200r006c00vv200r007c00+3 more2018-03-05
CVE-2017-17137 [MEDIUM] CWE-125 CVE-2017-17137: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2016-8785P4MEDIUMCVSS 4.3vv200r007c002018-03-09
CVE-2016-8785 [MEDIUM] CWE-20 CVE-2016-8785: Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory dat
nvd