Huawei S6700 Firmware vulnerabilities
35 known vulnerabilities affecting huawei/s6700_firmware.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM14LOW1
Vulnerabilities
Page 1 of 2
CVE-2021-37129HIGHCVSS 7.5vv200r010c00spc600vv200r011c10spc500+1 more2021-10-27
CVE-2021-37129 [HIGH] CWE-787 CVE-2021-37129: There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused b
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005
nvd
CVE-2021-22357HIGHCVSS 7.5vv200r013c00spc500vv200r019c00spc5002021-08-23
CVE-2021-22357 [HIGH] CWE-20 CVE-2021-22357: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages due to validating inputs insufficiently. Attackers can exploit this vulnerability by sending specific messages to affected module. This can cause denial of service. Affected product versions include: S12700 V200R013C00SPC500, V200R019C00SPC500; S5
nvd
CVE-2021-22329MEDIUMCVSS 4.9vv200r008c00vv200r010c00spc300+4 more2021-06-29
CVE-2021-22329 [MEDIUM] CVE-2021-22329: There has a license management vulnerability in some Huawei products. An attacker with high privileg
There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S1
nvd
CVE-2021-22377HIGHCVSS 7.2vv200r019c00spc5002021-06-22
CVE-2021-22377 [HIGH] CWE-20 CVE-2021-22377: There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S57
There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameters to inject command. This can compromise normal servic
nvd
CVE-2021-22359HIGHCVSS 7.5vv200r005c00spc5002021-05-27
CVE-2021-22359 [HIGH] CWE-20 CVE-2021-22359: There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C
There is a denial of service vulnerability in the verisions V200R005C00SPC500 of S5700 and V200R005C00SPC500 of S6700. An attacker could exploit this vulnerability by sending specific message to a targeted device. Due to insufficient input validation, successful exploit can cause the service abnormal.
nvd
CVE-2021-22321MEDIUMCVSS 5.3vv200r008c00vv200r010c00+5 more2021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2020-1866MEDIUMCVSS 6.5vv200r008c002021-01-13
CVE-2020-1866 [MEDIUM] CWE-125 CVE-2020-1866: There is an out-of-bounds read vulnerability in several products. The software reads data past the e
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700
nvd
CVE-2020-1810MEDIUMCVSS 5.3vv200r005c00spc500vv200r005c012020-01-09
CVE-2020-1810 [MEDIUM] CWE-327 CVE-2020-1810: There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA a
There is a weak algorithm vulnerability in some Huawei products. The affected products use the RSA algorithm in the SSL key exchange algorithm which have been considered as a weak algorithm. Attackers may exploit this vulnerability to leak some information.
nvd
CVE-2019-5304HIGHCVSS 7.5vv200r005c00vv200r005c01+4 more2020-01-03
CVE-2019-5304 [HIGH] CWE-120 CVE-2019-5304: Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could se
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.
nvd
CVE-2019-19397HIGHCVSS 7.5vv200r005c00vv200r005c01+6 more2019-12-13
CVE-2019-19397 [HIGH] CVE-2019-19397: There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algo
There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks.
nvd
CVE-2019-5290MEDIUMCVSS 6.5vv200r005c00spc500vv200r005c01+2 more2019-12-13
CVE-2019-5290 [MEDIUM] CVE-2019-5290: Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform
Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed properly, the vulnerability can be exploited to cause the device to be abnormal.
nvd
CVE-2019-5291MEDIUMCVSS 5.9vv200r008c00vv200r010c00spc300+2 more2019-12-13
CVE-2019-5291 [MEDIUM] CWE-345 CVE-2019-5291: Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote,
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerabil
nvd
CVE-2019-5285HIGHCVSS 7.5vv200r003c00vv200r005c00+6 more2019-06-04
CVE-2019-5285 [HIGH] CWE-20 CVE-2019-5285: Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send
Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send crafted packets to the affected device to exploit this vulnerability. Due to insufficient verification of the packets, successful exploitation may cause the device reboot and denial of service (DoS) condition. (Vulnerability ID: HWPSIRT-2019-03109)
nvd
CVE-2016-8786HIGHCVSS 7.5vv200r008c002018-03-09
CVE-2016-8786 [HIGH] CWE-20 CVE-2016-8786: Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V2
Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V200R008C00, S6700 V200R008C00, S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00 have a denial of service (DoS) vu
nvd
CVE-2017-17250MEDIUMCVSS 6.5vv200r008c002018-03-09
CVE-2017-17250 [MEDIUM] CWE-787 CVE-2017-17250: Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V20
Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300 V200R005C32; SRG2300 V200R005C32; SRG3300 V200R005C32 have an out-of-boun
nvd
CVE-2017-17136MEDIUMCVSS 5.5vv200r008c00vv200r009c00+1 more2018-03-05
CVE-2017-17136 [MEDIUM] CWE-119 CVE-2017-17136: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-17135MEDIUMCVSS 5.5vv200r008c00vv200r009c00+1 more2018-03-05
CVE-2017-17135 [MEDIUM] CWE-476 CVE-2017-17135: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-17137MEDIUMCVSS 5.5vv200r008c00vv200r009c00+1 more2018-03-05
CVE-2017-17137 [MEDIUM] CWE-125 CVE-2017-17137: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-17138MEDIUMCVSS 5.5vv200r008c00vv200r009c00+1 more2018-03-05
CVE-2017-17138 [MEDIUM] CWE-20 CVE-2017-17138: PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R
PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10; V200R007
nvd
CVE-2017-17141LOWCVSS 3.7vv200r001c00vv200r001c01+7 more2018-03-05
CVE-2017-17141 [LOW] CWE-772 CVE-2017-17141: Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009
Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009C00;S1700 V200R006C10; V200R009C00;S2700 V100R006C03; V200R003C00; V200R005C00; V200R006C00; V200R006C10; V200R007C00; V200R007C00B050; V200R007C00SPC009T; V200R007C00SPC019T; V200R008C00; V200R009C00;S3700 V100R006C03;S5700 V200R001C00; V200R001C01; V20
nvd
1 / 2Next →