Huawei Secospace Usg6600 Firmware vulnerabilities
88 known vulnerabilities affecting huawei/secospace_usg6600_firmware.
Total CVEs
88
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH34MEDIUM49LOW3
Vulnerabilities
Page 2 of 5
CVE-2020-1816P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1816 [HIGH] CVE-2020-1816: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Denial of Service (DoS) vulnerability. Due to improper processing of specific IPSEC packets, remote attackers can send constructed IPSEC packets to affected devices to exp
nvd
CVE-2020-1827P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1827 [HIGH] CWE-404 CVE-2020-1827: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful
nvd
CVE-2017-8147P3HIGHCVSS 7.5vv500r001c00vv500r001c20+1 more2017-11-22
CVE-2017-8147 [HIGH] CWE-20 CVE-2017-8147: AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C
AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with software V100R003C00, V100R005C00, V100R005
nvd
CVE-2017-17155P3HIGHCVSS 7.5vv500r001c00vv500r001c00spc100+15 more2018-02-15
CVE-2017-17155 [HIGH] CWE-787 CVE-2017-17155: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00
nvd
CVE-2020-1858P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1858 [HIGH] CVE-2020-1858: Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace US
Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100; and USG9500 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have a denial of service vulnerability. Attackers need to perform a series of operations in a special scen
nvd
CVE-2020-1847P3HIGHCVSS 7.5vv500r001c30vv500r001c602020-11-13
CVE-2020-1847 [HIGH] CVE-2020-1847: There is a denial of service vulnerability in some Huawei products. There is no protection against t
There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific protocol. A remote, unauthorized attackers can construct attack scenarios, which leads to denial of service.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospac
nvd
CVE-2020-9213P3HIGHCVSS 7.5vv500r001c30vv500r001c60+1 more2021-03-22
CVE-2020-9213 [HIGH] CVE-2020-9213: There is a denial of service vulnerability in some huawei products. In specific scenarios, due to th
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500, Se
nvd
CVE-2017-17256P3HIGHCVSS 7.5vv100r001c00spc200vv100r001c10+7 more2018-04-24
CVE-2017-17256 [HIGH] CWE-772 CVE-2017-17256: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2017-17257P3HIGHCVSS 7.5vv100r001c00spc200vv100r001c10+7 more2018-04-24
CVE-2017-17257 [HIGH] CWE-772 CVE-2017-17257: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13,
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2016-4577P3HIGHCVSS 7.5vv500r001c002016-05-23
CVE-2016-4577 [HIGH] CWE-119 CVE-2016-4577: Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
nvd
CVE-2020-1828P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1828 [HIGH] CWE-20 CVE-2020-1828: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and U
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message. Attackers can send specific message to cause out-of-boun
nvd
CVE-2020-1829P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+1 more2020-02-17
CVE-2020-1829 [HIGH] CWE-415 CVE-2020-1829: Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 version
Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Attackers can send specific message to cause double free memory. This may compromise normal service.
nvd
CVE-2021-22320P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+5 more2021-03-22
CVE-2021-22320 [HIGH] CVE-2021-22320: There is a denial of service vulnerability in Huawei products. A module cannot deal with specific me
There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace
nvd
CVE-2017-8174P3HIGHCVSS 7.5vv100r001c30spc500vv100r001c30spc600+2 more2017-11-22
CVE-2017-8174 [HIGH] CWE-326 CVE-2017-8174: Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V1
Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and cause confidential information leaks on the transmission links.
nvd
CVE-2020-1815P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1815 [HIGH] CWE-401 CVE-2020-1815: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability. The software does not sufficiently track and release allocated memory while parse certain message, the attacker sends the message contin
nvd
CVE-2020-9075P3MEDIUMCVSS 6.5vv500r001c30vv500r001c50+2 more2020-06-15
CVE-2020-9075 [MEDIUM] CWE-20 CVE-2020-9075: Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500
Huawei products Secospace USG6300;USG6300E with versions of V500R001C30,V500R001C50,V500R001C60,V500R001C80,V500R005C00,V500R005C10;V600R006C00 have a vulnerability of insufficient input verification. An attacker with limited privilege can exploit this vulnerability to access a specific directory. Successful exploitation of this vulnerability may lead
nvd
CVE-2021-22411P3MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+3 more2021-05-27
CVE-2021-22411 [MEDIUM] CWE-787 CVE-2021-22411: There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a b
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the module.Affected product versions include: NGFW
nvd
CVE-2016-8781P4MEDIUMCVSS 6.5vv500r001c20vv500r001c20spc200pwe2017-04-02
CVE-2016-8781 [MEDIUM] CWE-399 CVE-2016-8781: Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with
Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a device and deliver a large number of unspecified commands to exhaust memory, causing a DoS condition
nvd
CVE-2021-22312P4MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+3 more2021-04-08
CVE-2021-22312 [MEDIUM] CWE-401 CVE-2021-22312: There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may e
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Sec
nvd
CVE-2017-17153P4HIGHCVSS 7.5vv500r001c00vv500r001c00spc100+15 more2018-02-15
CVE-2017-17153 [HIGH] CWE-20 CVE-2017-17153: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00S
nvd