Huawei Technologies Co Ltd Uma vulnerabilities
15 known vulnerabilities affecting huawei_technologies_co_ltd/uma.
Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH1MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2017-15329P3HIGHCVSS 8.8vV200R001C002018-02-15
CVE-2017-15329 [HIGH] CWE-89 CVE-2017-15329: Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An
Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation ma
nvd
CVE-2017-8122P3CRITICALCVSS 9.8vV200R0012017-11-22
CVE-2017-8122 [CRITICAL] CWE-20 CVE-2017-8122: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8117P3CRITICALCVSS 9.8vV200R001 and V300R0012017-11-22
CVE-2017-8117 [CRITICAL] CWE-20 CVE-2017-8117: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8123P3CRITICALCVSS 9.8vV200R0012017-11-22
CVE-2017-8123 [CRITICAL] CWE-20 CVE-2017-8123: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8129P3CRITICALCVSS 9.8vV200R001 and V300R0012017-11-22
CVE-2017-8129 [CRITICAL] CWE-20 CVE-2017-8129: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8128P3CRITICALCVSS 9.8vV200R001 and V300R0012017-11-22
CVE-2017-8128 [CRITICAL] CWE-20 CVE-2017-8128: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8119P3CRITICALCVSS 9.8vV200R001 and V300R0012017-11-22
CVE-2017-8119 [CRITICAL] CWE-20 CVE-2017-8119: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8120P3CRITICALCVSS 9.8vV200R001 and V300R0012017-11-22
CVE-2017-8120 [CRITICAL] CWE-20 CVE-2017-8120: The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to i
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8126P3CRITICALCVSS 9.8vV200R0012017-11-22
CVE-2017-8126 [CRITICAL] CWE-20 CVE-2017-8126: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8124P3CRITICALCVSS 9.8vV200R0012017-11-22
CVE-2017-8124 [CRITICAL] CWE-20 CVE-2017-8124: The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
nvd
CVE-2017-8130P4MEDIUMCVSS 6.5vV200R001 and V300R0012017-11-22
CVE-2017-8130 [MEDIUM] CWE-200 CVE-2017-8130: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd
CVE-2017-8127P4MEDIUMCVSS 6.1vV200R0012017-11-22
CVE-2017-8127 [MEDIUM] CWE-79 CVE-2017-8127: The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insuffi
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
nvd
CVE-2017-8125P4MEDIUMCVSS 6.1vV200R001 and V300R0012017-11-22
CVE-2017-8125 [MEDIUM] CWE-79 CVE-2017-8125: The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability d
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
nvd
CVE-2017-8121P4MEDIUMCVSS 5.3vV200R0012017-11-22
CVE-2017-8121 [MEDIUM] CWE-200 CVE-2017-8121: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd
CVE-2017-8118P4LOWCVSS 2.3vV200R001 and V300R0012017-11-22
CVE-2017-8118 [LOW] CWE-200 CVE-2017-8118: The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attack
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
nvd