Huawei
Huawei UMA: vulnerabilidades y CVE
Huawei UMA tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-8130 | Media (6.5) | 0.73% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak. |
| CVE-2017-8129 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8128 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8127 | Media (6.1) | 0.55% | — | 22 nov 2017 | The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks. |
| CVE-2017-8126 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8125 | Media (6.1) | 0.55% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks. |
| CVE-2017-8124 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8123 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8122 | Crítica (9.8) | 1.3% | — | 22 nov 2017 | The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8121 | Media (5.3) | 0.75% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak. |
| CVE-2017-8120 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8119 | Crítica (9.8) | 1.0% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2017-8118 | Baja (2.3) | 0.23% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak. |
| CVE-2017-8117 | Crítica (9.8) | 1.1% | — | 22 nov 2017 | The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these… |
| CVE-2016-7110 | Crítica (9.8) | 2.7% | — | 7 sept 2016 | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7109. |
| CVE-2016-7109 | Crítica (9.8) | 3.5% | — | 7 sept 2016 | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110. |
| CVE-2016-7108 | Media (6.5) | 1.1% | — | 7 sept 2016 | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors. |
| CVE-2016-7107 | Alta (7.5) | 1.2% | — | 7 sept 2016 | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently affect system data integrity via unspecified vectors. |