cbcvebase.

Huawei Usg9500 Firmware vulnerabilities

81 known vulnerabilities affecting huawei/usg9500_firmware.

Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH38MEDIUM37LOW4

Vulnerabilities

Page 2 of 5
CVE-2021-37129P3HIGHCVSS 7.5vv500r005c00vv500r005c202021-10-27
CVE-2021-37129 [HIGH] CWE-787 CVE-2021-37129: There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused b There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected product versions include:IPS Module V500R005C00,V500R005C20;NGFW Module V500R005
nvd
CVE-2017-17154P3HIGHCVSS 7.5vv500r001c00vv500r001c00spc200+15 more2018-02-15
CVE-2017-17154 [HIGH] CWE-20 CVE-2017-17154: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50 IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00S
nvd
CVE-2017-17156P3HIGHCVSS 7.5vv500r001c00vv500r001c00spc200+15 more2018-02-15
CVE-2017-17156 [HIGH] CWE-20 CVE-2017-17156: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50 IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00S
nvd
CVE-2017-17157P3HIGHCVSS 7.5vv500r001c00vv500r001c00spc200+15 more2018-02-15
CVE-2017-17157 [HIGH] CWE-20 CVE-2017-17157: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50 IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00S
nvd
CVE-2020-1816P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1816 [HIGH] CVE-2020-1816: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Denial of Service (DoS) vulnerability. Due to improper processing of specific IPSEC packets, remote attackers can send constructed IPSEC packets to affected devices to exp
nvd
CVE-2020-1827P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1827 [HIGH] CWE-404 CVE-2020-1827: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful
nvd
CVE-2017-8167P3HIGHCVSS 7.5vv500r001c502017-11-22
CVE-2017-8167 [HIGH] CWE-20 CVE-2017-8167: Huawei firewall products USG9500 V500R001C50 has a DoS vulnerability.A remote attacker who controls Huawei firewall products USG9500 V500R001C50 has a DoS vulnerability.A remote attacker who controls the peer device could exploit the vulnerability by sending malformed IKE packets to the target device. Successful exploit of the vulnerability could cause the device to restart.
nvd
CVE-2017-17155P3HIGHCVSS 7.5vv500r001c00vv500r001c00spc200+15 more2018-02-15
CVE-2017-17155 [HIGH] CWE-787 CVE-2017-17155: IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V50 IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, NGFW Module V500R001C00, V500R001C00SPC200, V500R001C00
nvd
CVE-2020-1858P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1858 [HIGH] CVE-2020-1858: Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace US Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100; and USG9500 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have a denial of service vulnerability. Attackers need to perform a series of operations in a special scen
nvd
CVE-2020-1847P3HIGHCVSS 7.5vv500r001c30vv500r001c602020-11-13
CVE-2020-1847 [HIGH] CVE-2020-1847: There is a denial of service vulnerability in some Huawei products. There is no protection against t There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific protocol. A remote, unauthorized attackers can construct attack scenarios, which leads to denial of service.Affected product versions include:NIP6300 versions V500R001C30,V500R001C60;NIP6600 versions V500R001C30,V500R001C60;Secospac
nvd
CVE-2020-9213P3HIGHCVSS 7.5vv500r001c30vv500r001c60+1 more2021-03-22
CVE-2020-9213 [HIGH] CVE-2020-9213: There is a denial of service vulnerability in some huawei products. In specific scenarios, due to th There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the packets, an attacker may craft many specific packets. Successful exploit may cause some services to be abnormal. Affected products include some versions of NGFW Module, NIP6300, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500, Se
nvd
CVE-2017-17256P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17256 [HIGH] CWE-772 CVE-2017-17256: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2017-17257P3HIGHCVSS 7.5vv500r001c00vv500r001c20+2 more2018-04-24
CVE-2017-17257 [HIGH] CWE-772 CVE-2017-17257: Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30, AR150-S V200R006C10SPC300, V200R007C00, V200
nvd
CVE-2016-4577P3HIGHCVSS 7.5vv500r001c002016-05-23
CVE-2016-4577 [HIGH] CWE-119 CVE-2016-4577: Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6 Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
nvd
CVE-2020-1828P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1828 [HIGH] CWE-20 CVE-2020-1828: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and U Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message. Attackers can send specific message to cause out-of-boun
nvd
CVE-2020-1829P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+1 more2020-02-17
CVE-2020-1829 [HIGH] CWE-415 CVE-2020-1829: Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 version Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, and V500R001C60SPC500 have a vulnerability that the IPSec module handles a message improperly. Attackers can send specific message to cause double free memory. This may compromise normal service.
nvd
CVE-2019-5275P3HIGHCVSS 7.5vv500r001c30vv500r001c602019-12-26
CVE-2019-5275 [HIGH] CWE-787 CVE-2019-5275: USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a fl USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a heap buffer overflow when decoding a certificate, an attacker may exploit the vulnerability by a malicious certificate to perform a denial of service attack on the affected prod
nvd
CVE-2020-1815P3HIGHCVSS 7.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1815 [HIGH] CWE-401 CVE-2020-1815: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a memory leak vulnerability. The software does not sufficiently track and release allocated memory while parse certain message, the attacker sends the message contin
nvd
CVE-2019-5273P3HIGHCVSS 7.5vv500r001c30vv500r001c602019-12-26
CVE-2019-5273 [HIGH] CWE-120 CVE-2019-5273: USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a fl USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attacker may exploit the vulnerability by a malicious certificate, resulting a denial of service on the affected products.
nvd
CVE-2019-5274P3HIGHCVSS 7.5vv500r001c30vv500r001c602019-12-26
CVE-2019-5274 [HIGH] CWE-835 CVE-2019-5274: USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a fl USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in an infinite loop, an attacker may exploit the vulnerability via a malicious certificate to perform a denial of service attack on the affected products.
nvd
Huawei Usg9500 Firmware vulnerabilities | cvebase