Page 2 of 13 results (0.010 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges. El producto UMA con software V200R001 y V300R001 tiene una vulnerabilidad de elevación de privilegios debido a una validación insuficiente o al procesamiento incorrecto de parámetros. Un atacante podría manipular paquetes específicos para explotar estas vulnerabilidades y obtener privilegios elevados. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170612-01-uma-en • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 0

The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks. El producto UMA con software V200R001 y V300R001 tiene una vulnerabilidad de Cross-Site Scripting (XSS) debido a una validación de entradas insuficiente. Un atacante podría manipular enlaces o scripts maliciosos para lanzar ataques de XSS. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170612-01-uma-en • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges. El producto UMA con software V200R001 y V300R001 tiene una vulnerabilidad de elevación de privilegios debido a una validación insuficiente o al procesamiento incorrecto de parámetros. Un atacante podría manipular paquetes específicos para explotar estas vulnerabilidades y obtener privilegios elevados. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170612-01-uma-en • CWE-20: Improper Input Validation •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges. El producto UMA con software V200R001 y V300R001 tiene una vulnerabilidad de elevación de privilegios debido a una validación insuficiente o al procesamiento incorrecto de parámetros. Un atacante podría manipular paquetes específicos para explotar estas vulnerabilidades y obtener privilegios elevados. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170612-01-uma-en • CWE-20: Improper Input Validation •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110. Huawei Unified Maintenance Audit (UMA) en versiones anteriores a V200R001C00SPC200 permite a atacantes remotos ejecutar comandos arbitrarios a través de "caracteres especiales", una vulnerabilidad diferente a CVE-2016-7110. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-uma-en http://www.securityfocus.com/bid/92617 • CWE-94: Improper Control of Generation of Code ('Code Injection') •