Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.78% | — | Huawei Espace 7950 Firmware | 27/11/2018 | 17/6/2026 | There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept the packets in non-secure transmission mode. Successful exploitation may intercept and tamper with the call information, eventually cause sensitive information leak. | |
| Modificada | Media (5.9) | 0.78% | — | Huawei Espace 7950 Firmware | 27/11/2018 | 17/6/2026 | There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information leak. | |
| Modificada | Alta (7.4) | 1.1% | — | Huawei Espace 7950 Firmware | 27/11/2018 | 17/6/2026 | There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS. Due to insufficient authentication, which may be exploited to intercept and… | |
| Modificada | Alta (8.8) | 2.0% | — | Huawei Espace 7910 FirmwareHuawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 9/3/2018 | 17/6/2026 | Huawei eSpace 7910 V200R003C30; eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 have a directory traversal vulnerability. An authenticated, remote attacker can craft specific URL to the affected products. Due to insufficient verification of the URL, successful exploit will upload and download files and… | |
| Modificada | Alta (8.8) | 1.2% | — | Huawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 9/3/2018 | 17/6/2026 | Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due to insufficient verification of the… | |
| Modificada | Alta (8.8) | 1.2% | — | Huawei Espace 7950 FirmwareHuawei Espace 8950 Firmware | 9/3/2018 | 17/6/2026 | Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to insufficient verification of the packets,… | |
| Modificada | Alta (8.8) | 1.2% | — | Huawei Dp300 FirmwareHuawei Te60 FirmwareHuawei Tp3106 FirmwareHuawei Viewpoint 9030 Firmware+4 | 22/11/2017 | 17/6/2026 | DP300 V500R002C00,TE60 with software V100R001C01, V100R001C10, V100R003C00, V500R002C00 and V600R006C00,TP3106 with software V100R001C06 and V100R002C00,ViewPoint 9030 with software V100R011C02, V100R011C03,eCNS210_TD with software V100R004C10,eSpace 7950 with software V200R003C00 and V200R003C30,eSpace IAD with… |