Huawei
Huawei Manageone: vulnerabilidades y CVE
Huawei Manageone tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-37131 | Media (6.8) | 0.58% | — | 27 oct 2021 | There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to… |
| CVE-2021-22397 | Media (6.7) | 0.17% | — | 2 ago 2021 | There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these… |
| CVE-2021-22340 | Media (4.1) | 0.11% | — | 29 jun 2021 | There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by… |
| CVE-2021-22409 | Media (5.3) | 0.49% | — | 20 may 2021 | There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an… |
| CVE-2021-22339 | Media (6.5) | 0.28% | — | 20 may 2021 | There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit… |
| CVE-2021-22314 | Alta (7.8) | 0.18% | — | 22 mar 2021 | There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the… |
| CVE-2021-22311 | Alta (7.2) | 0.73% | — | 22 mar 2021 | There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do… |
| CVE-2021-22293 | Alta (7.5) | 0.91% | — | 6 feb 2021 | Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions… |
| CVE-2021-22299 | Alta (7.8) | 0.23% | — | 6 feb 2021 | There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to… |
| CVE-2021-22298 | Media (6.5) | 0.91% | — | 6 feb 2021 | There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform specific SQL statement to exploit this vulnerability. Due to insufficient security design, successful… |
| CVE-2020-9205 | Media (4.9) | 0.62% | — | 6 feb 2021 | There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some… |
| CVE-2020-9115 | Alta (7.2) | 1.4% | — | 1 dic 2020 | ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through… |
| CVE-2020-1862 | Baja (3.3) | 0.19% | — | 20 mar 2020 | There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some… |
| CVE-2019-5289 | Alta (7.5) | 0.74% | — | 13 nov 2019 | Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the… |
| CVE-2019-14835 | Alta (7.8) | 0.62% | — | 17 sept 2019 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged… |