cbcvebase.

Huawei Usg9500 Firmware vulnerabilities

81 known vulnerabilities affecting huawei/usg9500_firmware.

Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH38MEDIUM37LOW4

Vulnerabilities

Page 1 of 5
CVE-2020-9099P3CRITICALCVSS 9.8vv500r001c00vv500r001c20+7 more2020-06-08
CVE-2020-9099 [CRITICAL] CWE-287 CVE-2020-9099: Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG9500 with versions of V500R001C00; V500R001C20; V500R001C30; V500R001C50; V500R001C60; V500R001C80; V500R005C00; V500R005C10; V500R005C20; V500R002C00; V500R002C10; V500R002C20; V500R002C30 have an improper authentication v
nvd
CVE-2016-4576P3CRITICALCVSS 9.8vv500r001c002016-05-23
CVE-2016-4576 [CRITICAL] CWE-119 CVE-2016-4576: Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 devices with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, re
nvd
CVE-2014-9137P3HIGHCVSS 8.8≤ v200r001c01spc800vv300r001c002017-04-02
CVE-2014-9137 [HIGH] CWE-352 CVE-2014-9137: Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with softw Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
nvd
CVE-2020-1860P3HIGHCVSS 7.5vv500r001c30vv500r001c60+1 more2020-02-28
CVE-2020-1860 [HIGH] CVE-2020-1860: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005 NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be bypassed, and attackers can directly access the
nvd
CVE-2014-9136P3HIGHCVSS 8.8≤ v200r001c01spc800≤ v300r001c002017-04-02
CVE-2014-9136 [HIGH] CWE-352 CVE-2014-9136: Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remot Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.
nvd
CVE-2020-1876P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-28
CVE-2020-1876 [HIGH] CWE-787 CVE-2020-1876: NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write vulnerability. An unauthenticated attacker crafts malformed packets with specific parameter and sends the packets to the affected products. Due to insufficient validation of packets, which may be exploited to cause the process
nvd
CVE-2020-1871P3HIGHCVSS 8.2vv500r001c30spc100vv500r001c30spc200+10 more2020-01-03
CVE-2020-1871 [HIGH] CVE-2020-1871: USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C00SPC200 have an improper credentials management vulnerability. The software does not properly manage certain credentials. Successful exploit could cause information disclosure or damage, and impact the confidentiality or integrity.
nvd
CVE-2017-15348P3HIGHCVSS 7.5vv500r001c002018-02-15
CVE-2017-15348 [HIGH] CWE-20 CVE-2017-15348: Huawei IPS Module V500R001C00, NGFW Module V500R001C00, NIP6300 V500R001C00, NIP6600 V500R001C00, Se Huawei IPS Module V500R001C00, NGFW Module V500R001C00, NIP6300 V500R001C00, NIP6600 V500R001C00, Secospace USG6300 V500R001C00, Secospace USG6500 V500R001C00, Secospace USG6600 V500R001C00, USG9500 V500R001C00 have an insufficient input validation vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the
nvd
CVE-2020-1856P3HIGHCVSS 7.5vv500r001c30vv500r001c60+1 more2020-02-17
CVE-2020-1856 [HIGH] CVE-2020-1856: Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V50 Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V500R005C00 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful exploit may lead to information leakage.
nvd
CVE-2019-19411P4LOWCVSS 3.7PoCvv500r001c30spc100vv500r001c30spc200+5 more2020-01-21
CVE-2019-19411 [LOW] CWE-665 CVE-2019-19411: USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit thi
nvd
CVE-2017-17255P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17255 [HIGH] CWE-476 CVE-2017-17255: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2017-17253P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17253 [HIGH] CWE-125 CVE-2017-17253: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2017-17258P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17258 [HIGH] CWE-20 CVE-2017-17258: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200R
nvd
CVE-2017-17254P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17254 [HIGH] CWE-476 CVE-2017-17254: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2019-19416P3HIGHCVSS 7.5vv300r001c01vv300r001c20+4 more2020-07-08
CVE-2019-19416 [HIGH] CWE-20 CVE-2019-19416: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19417P3HIGHCVSS 7.5vv300r001c01vv300r001c20+4 more2020-07-08
CVE-2019-19417 [HIGH] CWE-20 CVE-2019-19417: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2019-19415P3HIGHCVSS 7.5vv300r001c01vv300r001c20+4 more2020-07-08
CVE-2019-19415 [HIGH] CWE-20 CVE-2019-19415: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attack The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leadin
nvd
CVE-2020-1881P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc6002020-02-28
CVE-2020-1881 [HIGH] CVE-2020-1881: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005 NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have have a resource management error vulnerability. An attacker needs to perform specific operations to trigger a function of the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service
nvd
CVE-2020-1873P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-28
CVE-2020-1873 [HIGH] CWE-125 CVE-2020-1873: NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005 NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the
nvd
CVE-2021-22309P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c60spc500+1 more2021-03-22
CVE-2021-22309 [HIGH] CWE-330 CVE-2021-22309: There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a s There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520
nvd
Huawei Usg9500 Firmware vulnerabilities | cvebase