Huawei Secospace Usg6300 Firmware vulnerabilities
67 known vulnerabilities affecting huawei/secospace_usg6300_firmware.
Total CVEs
67
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM40LOW3
Vulnerabilities
Page 4 of 4
CVE-2017-15338LOWCVSS 3.7vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-15338 [LOW] CWE-119 CVE-2017-15338: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-15339LOWCVSS 3.7vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-15339 [LOW] CWE-119 CVE-2017-15339: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-8174HIGHCVSS 7.5vv100r001c30spc3002017-11-22
CVE-2017-8174 [HIGH] CWE-326 CVE-2017-8174: Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V1
Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and cause confidential information leaks on the transmission links.
nvd
CVE-2016-8802MEDIUMCVSS 6.5vv500r001c20spc100vv500r001c20spc101+1 more2017-04-02
CVE-2016-8802 [MEDIUM] CWE-119 CVE-2016-8802: The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V
The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200 allows authenticated attackers to setup
nvd
CVE-2016-8781MEDIUMCVSS 6.5vv500r001c20vv500r001c20spc200pwe2017-04-02
CVE-2016-8781 [MEDIUM] CWE-399 CVE-2016-8781: Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with
Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a device and deliver a large number of unspecified commands to exhaust memory, causing a DoS condition
nvd
CVE-2016-4576CRITICALCVSS 9.8vv500r001c002016-05-23
CVE-2016-4576 [CRITICAL] CWE-119 CVE-2016-4576: Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, re
nvd
CVE-2016-4577HIGHCVSS 7.5vv500r001c002016-05-23
CVE-2016-4577 [HIGH] CWE-119 CVE-2016-4577: Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
nvd
← Previous4 / 4