cbcvebase.

Huawei Usg9500 Firmware vulnerabilities

81 known vulnerabilities affecting huawei/usg9500_firmware.

Total CVEs
81
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH38MEDIUM37LOW4

Vulnerabilities

Page 4 of 5
CVE-2021-22321P4MEDIUMCVSS 5.3vv500r001c30vv500r001c602021-03-22
CVE-2021-22321 [MEDIUM] CWE-416 CVE-2021-22321: There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific oper There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. Attackers can exploit this vulnerability by performing malicious operations. This can cause memory use-after-free, compromising normal service. Affected product include some versions of NIP6300, NIP6600, NIP6800, S1700, S2
nvd
CVE-2020-9201P4MEDIUMCVSS 6.5vv500r001c30spc200vv500r001c30spc600+2 more2020-12-24
CVE-2020-9201 [MEDIUM] CWE-125 CVE-2020-9201: There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9 There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal.
nvd
CVE-2020-1814P4MEDIUMCVSS 5.3vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1814 [MEDIUM] CWE-119 CVE-2020-1814: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a Dangling pointer dereference vulnerability. An authenticated attacker may do some special operations in the affected products in some special scenarios to exploi
nvd
CVE-2021-22360P4MEDIUMCVSS 4.9vv500r001c60spc500vv500r005c00spc100+2 more2021-05-27
CVE-2021-22360 [MEDIUM] CWE-770 CVE-2021-22360: There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SP There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause s
nvd
CVE-2019-5272P4MEDIUMCVSS 4.9vv500r001c30vv500r001c602019-12-26
CVE-2019-5272 [MEDIUM] CWE-354 CVE-2019-5272: USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. Th USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.
nvd
CVE-2020-1830P4MEDIUMCVSS 5.3vv500r001c30spc200vv500r001c30spc600+2 more2020-02-18
CVE-2020-1830 [MEDIUM] CWE-125 CVE-2020-1830: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG95 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have a vulnerability that a memory management error exists when IPSec Module handing a specific message. This causes 1 byte out-of-bound read, compromising normal servi
nvd
CVE-2021-22342P4MEDIUMCVSS 4.9vv500r001c00vv500r001c20+7 more2021-06-22
CVE-2021-22342 [MEDIUM] CVE-2021-22342: There is an information leak vulnerability in Huawei products. A module does not deal with specific There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V500R005C00, V500R005C10, V500R005C20; NGFW Module versions V50
nvd
CVE-2020-1857P4MEDIUMCVSS 5.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-17
CVE-2020-1857 [MEDIUM] CVE-2020-1857: Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. Due to improper processing of some data, a local authenticated attacker can exploit this vulnerability through a seri
nvd
CVE-2020-1874P4MEDIUMCVSS 5.5vv500r001c30spc200vv500r001c30spc600+2 more2020-02-28
CVE-2020-1874 [MEDIUM] CWE-824 CVE-2020-1874: NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SP NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot.
nvd
CVE-2020-1875P4MEDIUMCVSS 5.5vv500r001c30spc200vv500r001c30spc600+1 more2020-02-28
CVE-2020-1875 [MEDIUM] CWE-824 CVE-2020-1875: NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SP NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when an abnormal condition occurs in certain operation. Successful exploit could cause certain process reboot. Affected product versions include:NIP6800 ver
nvd
CVE-2017-17138P4MEDIUMCVSS 5.5vv500r001c00vv500r001c302018-03-05
CVE-2017-17138 [MEDIUM] CWE-20 CVE-2017-17138: PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10; V200R007
nvd
CVE-2017-17136P4MEDIUMCVSS 5.5vv500r001c00vv500r001c302018-03-05
CVE-2017-17136 [MEDIUM] CWE-119 CVE-2017-17136: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2020-1883P4MEDIUMCVSS 4.9vv500r001c30spc200vv500r001c30spc600+4 more2020-06-05
CVE-2020-1883 [MEDIUM] CWE-401 CVE-2020-1883: Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.
nvd
CVE-2017-17162P4MEDIUMCVSS 5.5vv500r001c30spc100vv500r001c30spc200+1 more2018-02-15
CVE-2017-17162 [MEDIUM] CWE-772 CVE-2017-17162: Huawei Secospace USG6600 V500R001C30SPC100, Secospace USG6600 V500R001C30SPC200, Secospace USG6600 V Huawei Secospace USG6600 V500R001C30SPC100, Secospace USG6600 V500R001C30SPC200, Secospace USG6600 V500R001C30SPC300, USG9500 V500R001C30SPC100, USG9500 V500R001C30SPC200, USG9500 V500R001C30SPC300 have a memory leak vulnerability due to memory don't be released when an local authenticated attacker execute special commands many times. An attacker co
nvd
CVE-2017-17137P4MEDIUMCVSS 5.5vv500r001c00vv500r001c302018-03-05
CVE-2017-17137 [MEDIUM] CWE-125 CVE-2017-17137: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2017-17135P4MEDIUMCVSS 5.5vv500r001c00vv500r001c302018-03-05
CVE-2017-17135 [MEDIUM] CWE-476 CVE-2017-17135: PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00 PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600 V500R001C00; V500R001C30; RP200 V500R002C00; V600R006C00; S12700 V200R007C00; V200R007C01; V200R008C00; V200R009C00; V200R010C00; S1700 V200R006C10; V200R009C00; V200R010C00; S2700 V200R006C10;
nvd
CVE-2021-22310P4MEDIUMCVSS 4.4vv500r005c00vv500r005c102021-03-22
CVE-2021-22310 [MEDIUM] CWE-532 CVE-2021-22310: There is an information leakage vulnerability in some huawei products. Due to the properly storage o There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected product versions include: NIP6300 versions V500R001C00,V500R001C20,V500R001C3
nvd
CVE-2020-1877P4MEDIUMCVSS 4.4vv500r001c30spc200vv500r001c30spc600+2 more2020-02-28
CVE-2020-1877 [MEDIUM] CWE-824 CVE-2020-1877: NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful exploit could cause certain process reboot.
nvd
CVE-2017-15337P4LOWCVSS 3.7vv500r001c00vv500r001c20+1 more2018-02-15
CVE-2017-15337 [LOW] CWE-119 CVE-2017-15337: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
CVE-2017-15338P4LOWCVSS 3.7vv500r001c00vv500r001c20+1 more2018-02-15
CVE-2017-15338 [LOW] CWE-119 CVE-2017-15338: The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R0 The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, NGFW Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R002C00, V500R002C10, NIP6300 V500R001C00, V500R001C20, V500R001C30, V500R001C50, NIP6600 V500R001C00, V500R001C20, V500R001C30
nvd
Huawei Usg9500 Firmware vulnerabilities | cvebase