Huawei Secospace Usg6500 Firmware vulnerabilities
67 known vulnerabilities affecting huawei/secospace_usg6500_firmware.
Total CVEs
67
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM40LOW3
Vulnerabilities
Page 2 of 4
CVE-2017-17257P3HIGHCVSS 7.5vv100r001c10vv100r001c20+5 more2018-04-24
CVE-2017-17257 [HIGH] CWE-772 CVE-2017-17257: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2016-4577P3HIGHCVSS 7.5vv500r001c002016-05-23
CVE-2016-4577 [HIGH] CWE-119 CVE-2016-4577: Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
nvd
CVE-2021-22320P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+5 more2021-03-22
CVE-2021-22320 [HIGH] CVE-2021-22320: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace
nvd
CVE-2021-22411P3MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+3 more2021-05-27
CVE-2021-22411 [MEDIUM] CWE-787 CVE-2021-22411: There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a b
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the module.Affected product versions include: NGFW
nvd
CVE-2016-8781P4MEDIUMCVSS 6.5vv500r001c202017-04-02
CVE-2016-8781 [MEDIUM] CWE-399 CVE-2016-8781: Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with
Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a device and deliver a large number of unspecified commands to exhaust memory, causing a DoS condition
nvd
CVE-2021-22312P4MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+3 more2021-04-08
CVE-2021-22312 [MEDIUM] CWE-401 CVE-2021-22312: There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may e
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Sec
nvd
CVE-2017-17153P4HIGHCVSS 7.5vv500r001c00vv500r001c00spc200+14 more2018-02-15
CVE-2017-17153 [HIGH] CWE-20 CVE-2017-17153: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00S
nvd
CVE-2016-8802P4MEDIUMCVSS 6.5vv500r001c20spc100vv500r001c20spc101+1 more2017-04-02
CVE-2016-8802 [MEDIUM] CWE-119 CVE-2016-8802: The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V
The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200 allows authenticated attackers to setup
nvd
CVE-2017-15315P4MEDIUMCVSS 6.5vv500r001c20spc100vv500r001c20spc2002018-03-09
CVE-2017-15315 [MEDIUM] CWE-772 CVE-2017-15315: Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500
Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200 has a memory leak vulnerability. An authenticated attacker could execute special commands many times, the memory leaking happ
nvd
CVE-2020-9127P4MEDIUMCVSS 6.7vv500r001c30vv500r001c602020-11-13
CVE-2020-9127 [MEDIUM] CWE-20 CVE-2020-9127: Some Huawei products have a command injection vulnerability. Due to insufficient input validation, a
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,
nvd
CVE-2017-15331P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-15331 [MEDIUM] CWE-125 CVE-2017-15331: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10, V200R007C00, V200R008
nvd
CVE-2020-9101P4MEDIUMCVSS 6.5vv500r001c30vv500r001c60+2 more2020-07-18
CVE-2020-9101 [MEDIUM] CWE-787 CVE-2020-9101: There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts m
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process reboot. Affected product versions include: IPS Module versions V500R005C00, V
nvd
CVE-2021-22356P4MEDIUMCVSS 5.9vv500r001c30spc200vv500r001c30spc600+3 more2021-11-23
CVE-2021-22356 [MEDIUM] CWE-327 CVE-2021-22356: There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used i
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; N
nvd
CVE-2017-17166P4MEDIUMCVSS 5.3vv500r001c00vv500r001c20+2 more2018-02-15
CVE-2017-17166 [MEDIUM] CWE-400 CVE-2017-17166: Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Seco
Huawei DP300 V500R002C00, Secospace USG6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6500 V500R001C00, V500R001C20, V500R001C30, V500R001C50, Secospace USG6600 V500R001C00, V500R001C20, V500R001C30, V500R001C50, TP3206 V100R002C00, VP9660 V500R002C00, V500R002C10 have a resource exhaustion vulnerability. The software does not
nvd
CVE-2017-17295P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-17295 [MEDIUM] CWE-119 CVE-2017-17295: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10, V200R007C00, V200R008
nvd
CVE-2017-17297P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-17297 [MEDIUM] CWE-119 CVE-2017-17297: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10, V200R007C00, V200R008
nvd
CVE-2017-15350P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-02-15
CVE-2017-15350 [MEDIUM] CWE-119 CVE-2017-15350: The Common Open Policy Service Protocol (COPS) module in Huawei DP300 V500R002C00, IPS Module V100R0
The Common Open Policy Service Protocol (COPS) module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001
nvd
CVE-2017-17152P4MEDIUMCVSS 5.9vv500r001c00vv500r001c00spc200+14 more2018-02-15
CVE-2017-17152 [MEDIUM] CWE-20 CVE-2017-17152: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C0
nvd
CVE-2017-17251P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-04-24
CVE-2017-17251 [MEDIUM] CWE-476 CVE-2017-17251: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V2
nvd
CVE-2017-17252P4MEDIUMCVSS 5.3vv100r001c10vv100r001c20+5 more2018-04-24
CVE-2017-17252 [MEDIUM] CWE-125 CVE-2017-17252: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V2
nvd