Huawei Smc2.0 Firmware vulnerabilities

12 known vulnerabilities affecting huawei/smc2.0_firmware.

Total CVEs
12
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH4MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2021-22299HIGHCVSS 7.8vv600r019c00vv600r019c102021-02-06
CVE-2021-22299 [HIGH] CVE-2021-22299: There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions 6.5.0,6.5.0.SPC100.B210,6.5.1.1.B010,6.5.1.1.B020,6.5.1.1.B03
nvd
CVE-2020-9209MEDIUMCVSS 6.7vv600r006c00spc700vv600r006c00spc800+13 more2021-01-13
CVE-2020-9209 [MEDIUM] CWE-862 CVE-2020-9209: There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a modu There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the directory limitation. Attackers can exploit this vulnerability by crafting malicious file to launch privilege escalation. This can compromise normal service of affected products.
nvd
CVE-2019-19416HIGHCVSS 7.5vv100r003c00spc200tvv100r003c00spc300t+10 more2020-07-08
CVE-2019-19416 [HIGH] CWE-20 CVE-2019-19416: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19417HIGHCVSS 7.5vv100r003c00spc200tvv100r003c00spc300t+10 more2020-07-08
CVE-2019-19417 [HIGH] CWE-20 CVE-2019-19417: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19415HIGHCVSS 7.5vv100r003c00spc200tvv100r003c00spc300t+10 more2020-07-08
CVE-2019-19415 [HIGH] CWE-20 CVE-2019-19415: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-0708CRITICALCVSS 9.8KEVPoCvv500r002c00vv600r006c002019-05-16
CVE-2019-0708 [CRITICAL] CWE-416 CVE-2019-0708: A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal S A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2017-17301CRITICALCVSS 9.8vv100r003c10vv100r005c00+1 more2018-02-15
CVE-2017-17301 [CRITICAL] CWE-295 CVE-2017-17301: Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR1200 V200R005C20, V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR1200-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, AR160 V200R005C32, V200R006C10, V200R007C00, V200R007
nvd
CVE-2017-15332MEDIUMCVSS 5.3vv100r003c10vv100r005c00+4 more2018-02-15
CVE-2017-15332 [MEDIUM] CWE-772 CVE-2017-15332: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10, V200R007C00, V200R008
nvd
CVE-2017-15331MEDIUMCVSS 5.3vv100r003c10vv100r005c00+4 more2018-02-15
CVE-2017-15331 [MEDIUM] CWE-125 CVE-2017-15331: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10, V200R007C00, V200R008
nvd
CVE-2017-8162MEDIUMCVSS 6.5vv100r003c10vv100r005c00+2 more2017-11-22
CVE-2017-8162 [MEDIUM] CWE-119 CVE-2017-8162: AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R0 AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C3
nvd
CVE-2017-8163MEDIUMCVSS 6.5vv100r003c10vv100r005c00+2 more2017-11-22
CVE-2017-8163 [MEDIUM] CWE-125 CVE-2017-8163: AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R0 AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C3
nvd
CVE-2017-8213MEDIUMCVSS 5.3vv100r003c10vv100r005c00spc100+7 more2017-11-22
CVE-2017-8213 [MEDIUM] CWE-295 CVE-2017-8213: Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SP Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote a
nvd