Huawei Secospace Usg6600 Firmware vulnerabilities

88 known vulnerabilities affecting huawei/secospace_usg6600_firmware.

Total CVEs
88
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH34MEDIUM49LOW3

Vulnerabilities

Page 5 of 5
CVE-2017-15339LOWCVSS 3.7vv100r001c00vv100r001c20+5 more2018-02-15
CVE-2017-15339 [LOW] CWE-119 CVE-2017-15339: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-8147HIGHCVSS 7.5vv500r001c00vv500r001c20+1 more2017-11-22
CVE-2017-8147 [HIGH] CWE-20 CVE-2017-8147: AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C AC6005 V200R006C10SPC200,AC6605 V200R006C10SPC200,AR1200 with software V200R005C10CP0582T, V200R005C10HP0581T, V200R005C20SPC026T,AR200 with software V200R005C20SPC026T,AR3200 V200R005C20SPC026T,CloudEngine 12800 with software V100R003C00, V100R005C00, V100R005C10, V100R006C00, V200R001C00,CloudEngine 5800 with software V100R003C00, V100R005C00, V100R005
nvd
CVE-2017-8174HIGHCVSS 7.5vv100r001c30spc500vv100r001c30spc600+2 more2017-11-22
CVE-2017-8174 [HIGH] CWE-326 CVE-2017-8174: Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V1 Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and cause confidential information leaks on the transmission links.
nvd
CVE-2016-8802MEDIUMCVSS 6.5vv500r001c20spc100vv500r001c20spc101+1 more2017-04-02
CVE-2016-8802 [MEDIUM] CWE-119 CVE-2016-8802: The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200 allows authenticated attackers to setup
nvd
CVE-2016-8781MEDIUMCVSS 6.5vv500r001c20vv500r001c20spc200pwe2017-04-02
CVE-2016-8781 [MEDIUM] CWE-399 CVE-2016-8781: Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a device and deliver a large number of unspecified commands to exhaust memory, causing a DoS condition
nvd
CVE-2016-8795MEDIUMCVSS 5.9vv500r001c002017-04-02
CVE-2016-8795 [MEDIUM] CWE-190 CVE-2016-8795: Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 7800 w
nvd
CVE-2016-4576CRITICALCVSS 9.8vv500r001c002016-05-23
CVE-2016-4576 [CRITICAL] CWE-119 CVE-2016-4576: Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, re
nvd
CVE-2016-4577HIGHCVSS 7.5vv500r001c002016-05-23
CVE-2016-4577 [HIGH] CWE-119 CVE-2016-4577: Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6 Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
nvd