Huawei Uma vulnerabilities
18 known vulnerabilities affecting huawei/uma.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH1MEDIUM5LOW1
Vulnerabilities
Page 1 of 1
CVE-2017-8123CRITICALCVSS 9.8vv200r0012017-11-22
CVE-2017-8123 [CRITICAL] CWE-20 CVE-2017-8123: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8129CRITICALCVSS 9.8vv200r001vv300r0012017-11-22
CVE-2017-8129 [CRITICAL] CWE-20 CVE-2017-8129: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8122CRITICALCVSS 9.8vv200r0012017-11-22
CVE-2017-8122 [CRITICAL] CWE-20 CVE-2017-8122: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8128CRITICALCVSS 9.8vv200r001vv300r0012017-11-22
CVE-2017-8128 [CRITICAL] CWE-20 CVE-2017-8128: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8119CRITICALCVSS 9.8vv200r001vv300r0012017-11-22
CVE-2017-8119 [CRITICAL] CWE-20 CVE-2017-8119: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8120CRITICALCVSS 9.8vv200r001vv300r0012017-11-22
CVE-2017-8120 [CRITICAL] CWE-20 CVE-2017-8120: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8126CRITICALCVSS 9.8vv200r0012017-11-22
CVE-2017-8126 [CRITICAL] CWE-20 CVE-2017-8126: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8124CRITICALCVSS 9.8vv200r0012017-11-22
CVE-2017-8124 [CRITICAL] CWE-20 CVE-2017-8124: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8117CRITICALCVSS 9.8vv200r001vv300r0012017-11-22
CVE-2017-8117 [CRITICAL] CWE-20 CVE-2017-8117: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8130MEDIUMCVSS 6.5vv200r001vv300r0012017-11-22
CVE-2017-8130 [MEDIUM] CWE-200 CVE-2017-8130: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd
CVE-2017-8127MEDIUMCVSS 6.1vv200r0012017-11-22
CVE-2017-8127 [MEDIUM] CWE-79 CVE-2017-8127: The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insuffi
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
nvd
CVE-2017-8125MEDIUMCVSS 6.1vv200r001vv300r0012017-11-22
CVE-2017-8125 [MEDIUM] CWE-79 CVE-2017-8125: The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability d
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
nvd
CVE-2017-8121MEDIUMCVSS 5.3vv200r001vv300r0012017-11-22
CVE-2017-8121 [MEDIUM] CWE-200 CVE-2017-8121: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd
CVE-2017-8118LOWCVSS 2.3vv200r001vv300r0012017-11-22
CVE-2017-8118 [LOW] CWE-200 CVE-2017-8118: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd
CVE-2016-7110CRITICALCVSS 9.8≤ v200r001c00spc1002016-09-07
CVE-2016-7110 [CRITICAL] CVE-2016-7110: Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute a
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7109.
nvd
CVE-2016-7109CRITICALCVSS 9.8≤ v200r001c00spc1002016-09-07
CVE-2016-7109 [CRITICAL] CWE-94 CVE-2016-7109: Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute a
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110.
nvd
CVE-2016-7107HIGHCVSS 7.5≤ v200r001c00spc2002016-09-07
CVE-2016-7107 [HIGH] CWE-284 CVE-2016-7107: Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to re
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently affect system data integrity via unspecified vectors.
nvd
CVE-2016-7108MEDIUMCVSS 6.5≤ v200r001c00spc2002016-09-07
CVE-2016-7108 [MEDIUM] CWE-200 CVE-2016-7108: Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated u
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.
nvd