Huawei S7700 Firmware vulnerabilities
37 known vulnerabilities affecting huawei/s7700_firmware.
Total CVEs
37
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH19MEDIUM17LOW1
Vulnerabilities
Page 2 of 2
CVE-2014-5394P4MEDIUMCVSS 5.9vv200r001c00spc300vv200r002c00spc300+1 more2018-01-08
CVE-2014-5394 [MEDIUM] CWE-200 CVE-2014-5394: Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
nvd
CVE-2015-8677P4MEDIUMCVSS 6.5≥ v200r003c00, < v200r003sph011≥ v200r005c00, < v200r005sph009+1 more2016-04-14
CVE-2015-8677 [MEDIUM] CWE-399 CVE-2015-8677: Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V2
Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00 before V200R005SPH008, and V200R006C00 before V200R006SPH002; S9300, S7700, an
nvd
CVE-2020-1866P4MEDIUMCVSS 6.5vv200r008c002021-01-13
CVE-2020-1866 [MEDIUM] CWE-125 CVE-2020-1866: There is an out-of-bounds read vulnerability in several products. The software reads data past the e
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700
nvd
CVE-2021-22321P4MEDIUMCVSS 5.3vv200r008c00vv200r010c00+4 more2021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2014-8570P4MEDIUMCVSS 5.3vv100r002vv100r003+5 more2017-04-02
CVE-2014-8570 [MEDIUM] CWE-200 CVE-2014-8570: Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V
Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with software V200R002, V200R003, V200R005; S12708, S12712 with software V200R005; 5700HI, 5300HI with software
nvd
CVE-2021-22329P4MEDIUMCVSS 4.9vv200r008c00vv200r010c00spc300+3 more2021-06-29
CVE-2021-22329 [MEDIUM] CVE-2021-22329: There has a license management vulnerability in some Huawei products. An attacker with high privileg
There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be applied and affect integrity of the device. Affected product versions include:S1
nvd
CVE-2016-6670P4MEDIUMCVSS 5.3vv200r003c00vv200r005c002016-09-07
CVE-2016-6670 [MEDIUM] CWE-200 CVE-2016-6670: Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random num
Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.
nvd
CVE-2017-17138P4MEDIUMCVSS 5.5vv200r007c00vv200r008c00+2 more2018-03-05
CVE-2017-17138 [MEDIUM] CWE-20 CVE-2017-17138: PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R
PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10; V200R007
nvd
CVE-2017-17136P4MEDIUMCVSS 5.5vv200r007c00vv200r008c00+2 more2018-03-05
CVE-2017-17136 [MEDIUM] CWE-119 CVE-2017-17136: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-17137P4MEDIUMCVSS 5.5vv200r007c00vv200r008c00+2 more2018-03-05
CVE-2017-17137 [MEDIUM] CWE-125 CVE-2017-17137: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2016-8785P4MEDIUMCVSS 4.3vv200r002c00vv200r005c00+3 more2018-03-09
CVE-2016-8785 [MEDIUM] CWE-20 CVE-2016-8785: Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C
Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory dat
nvd
CVE-2017-15327P4MEDIUMCVSS 4.3vv200r001c00vv200r001c01+11 more2018-04-11
CVE-2017-15327 [MEDIUM] CWE-200 CVE-2017-15327: S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V2
S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S7700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S9700 V200R001C00, V200R001C01, V200R00
nvd
CVE-2017-17135P4MEDIUMCVSS 5.5vv200r007c00vv200r008c00+2 more2018-03-05
CVE-2017-17135 [MEDIUM] CWE-476 CVE-2017-17135: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-15346P4MEDIUMCVSS 4.7vv200r001c00vv200r002c00+7 more2018-02-15
CVE-2017-15346 [MEDIUM] CWE-20 CVE-2017-15346: XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C0
XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C02, V200R008C00, V200R009C00, V200R010C00,S7700
nvd
CVE-2017-15333P4MEDIUMCVSS 4.7vv200r001c00vv200r002c00+7 more2018-02-15
CVE-2017-15333 [MEDIUM] CWE-20 CVE-2017-15333: XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C0
XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R005C02, V200R008C00, V200R009C00, V200R010C00,S7700
nvd
CVE-2015-7846P4MEDIUMCVSS 4.6vv200r001c00spc300vv200r002c00spc100+4 more2017-09-25
CVE-2015-7846 [MEDIUM] CWE-200 CVE-2015-7846: Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R00
Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.
nvd
CVE-2017-17141P4LOWCVSS 3.7vv200r001c00vv200r001c01+10 more2018-03-05
CVE-2017-17141 [LOW] CWE-772 CVE-2017-17141: Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009
Huawei S12700 V200R005C00; V200R006C00; V200R007C00; V200R007C01; V200R007C20; V200R008C00; V200R009C00;S1700 V200R006C10; V200R009C00;S2700 V100R006C03; V200R003C00; V200R005C00; V200R006C00; V200R006C10; V200R007C00; V200R007C00B050; V200R007C00SPC009T; V200R007C00SPC019T; V200R008C00; V200R009C00;S3700 V100R006C03;S5700 V200R001C00; V200R001C01; V20
nvd
← Previous2 / 2