CVE-2014-9694
https://notcve.org/view.php?id=CVE-2014-9694
Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621 V2 V100R001C00SPC107 and earlier versions, Tecal DH628 V2 V100R001C00SPC107 and earlier versions, Tecal BH620 V2 V100R002C00SPC107 and earlier versions, Tecal BH621 V2 V100R002C00SPC106 and earlier versions, Tecal BH622 V2 V100R002C00SPC110 and earlier versions, Tecal BH640 V2 V100R002C00SPC108 and earlier versions, Tecal CH121 V100R001C00SPC180 and earlier versions, Tecal CH140 V100R001C00SPC110 and earlier versions, Tecal CH220 V100R001C00SPC180 and earlier versions, Tecal CH221 V100R001C00SPC180 and earlier versions, Tecal CH222 V100R002C00SPC180 and earlier versions, Tecal CH240 V100R001C00SPC180 and earlier versions, Tecal CH242 V100R001C00SPC180 and earlier versions, Tecal CH242 V3 V100R001C00SPC110 and earlier versions have a CSRF vulnerability. The products do not use the Token mechanism for web access control. When users log in to the Huawei servers and access websites containing the malicious CSRF script, the CSRF script is executed, which may cause configuration tampering and system restart. Huawei Tecal RH1288 V2 V100R002C00SPC107 y versiones anteriores, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 y versiones anteriores, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 y versiones anteriores, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 y versiones anteriores, Tecal RH2288H V2 V100R002C00SPC115 y versiones anteriores, Tecal RH2485 V2 V100R002C00SPC502 y versiones anteriores, Tecal RH5885 V2 V100R001C02SPC109 y versiones anteriores, Tecal RH5885 V3 V100R003C01SPC102 y versiones anteriores, Tecal RH5885H V3 V100R003C00SPC102 y versiones anteriores, Tecal XH310 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH311 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH320 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH621 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH310 V2 V100R001C00SPC110 y versiones anteriores, Tecal DH320 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH620 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH621 V2 V100R001C00SPC107 y versiones anteriores, Tecal DH628 V2 V100R001C00SPC107 y versiones anteriores, Tecal BH620 V2 V100R002C00SPC107 y versiones anteriores, Tecal BH621 V2 V100R002C00SPC106 y versiones anteriores, Tecal BH622 V2 V100R002C00SPC110 y versiones anteriores, Tecal BH640 V2 V100R002C00SPC108 y versiones anteriores, Tecal CH121 V100R001C00SPC180 y versiones anteriores, Tecal CH140 V100R001C00SPC110 y versiones anteriores, Tecal CH220 V100R001C00SPC180 y versiones anteriores, Tecal CH221 V100R001C00SPC180 y versiones anteriores, Tecal CH222 V100R002C00SPC180 y versiones anteriores, Tecal CH240 V100R001C00SPC180 y versiones anteriores, Tecal CH242 V100R001C00SPC180 y versiones anteriores, Tecal CH242 V3 V100R001C00SPC110 y versiones anteriores tienen una vulnerabilidad de CSRF. Los productos no utilizan el mecanismo Token para el control de acceso web. • http://www.huawei.com/en/psirt/security-advisories/hw-408100 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-6825
https://notcve.org/view.php?id=CVE-2016-6825
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms." Servidores Huawei XH620 V3, XH622 V3 y XH628 V3 con software en versiones anteriores a V100R03C00SPC610, servidores RH1288 V3 con software en versiones anteriores a V100R003C00SPC613, servidores RH2288 V3 con software en versiones anteriores a V100R003C00SPC617 y servidores RH2288H V3 con software en versiones anteriores a V100R003C00SPC515 permite a atacantes remotos obtener contraseñas a través de un ataque de fuerza bruta, relacionado con "la falta de mecanismos de protección de autenticación". • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160817-01-server-en http://www.securityfocus.com/bid/92504 • CWE-285: Improper Authorization •
CVE-2016-6838
https://notcve.org/view.php?id=CVE-2016-6838
Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, CH140 V3 and CH226 V3 servers with software before V100R001C00SPC122, CH220 V3 servers with software before V100R001C00SPC201, and CH121 V3 and CH222 V3 servers with software before V100R001C00SPC202 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSH encryption algorithm. Servidores Huawei X6800 y XH620 V3 con software en versiones anteriores a V100R003C00SPC606, servidores RH1288 V3 con software en versiones anteriores a V100R003C00SPC613, servidores RH2288 V3 con software en versiones anteriores a V100R003C00SPC617, CH140 V3 y servidores CH226 V3 con software en versiones anteriores a V100R001C00SPC122, servidores CH220 V3 con software en versiones anteriores a V100R001C00SPC201 y CH121 V3 y servidores CH222 V3 con software en versiones anteriores a V100R001C00SPC202 podría permitir a atacantes remotos desencripar datos encriptados y, consecuentemente, obtener información sensible mediante el aprovechamiento de la selección de un algoritmo de encriptación SSH inseguro. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160817-02-server-en http://www.securityfocus.com/bid/92503 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-310: Cryptographic Issues •
CVE-2016-6900
https://notcve.org/view.php?id=CVE-2016-6900
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613; RH2288 V3 servers with software before V100R003C00SPC617; RH2288H V3 servers with software before V100R003C00SPC515; RH5885 V3 servers with software before V100R003C10SPC102; and XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610 allows local users to cause a denial of service (iBMC resource consumption) via unspecified vectors. Intelligent Baseboard Management Controller (iBMC) en servidores Huawei RH1288 V3 con software anterior a V100R003C00SPC613; servidores RH2288 V3 con software anterior a V100R003C00SPC617; servidores RH2288H V3 con software anterior a V100R003C00SPC515; servidores RH5885 V3 con software anterior a V100R003C10SPC102 XH620 V3, XH622 V3 y servidores XH628 V3 con software anterior a V100R003C00SPC610 permite a usuarios locales provocar una denegación de servicio (recurso de consumo iBMC) a través de vectores no especificados. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-server-en • CWE-399: Resource Management Errors •
CVE-2016-6899
https://notcve.org/view.php?id=CVE-2016-6899
The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, RH2288H V3 servers with software before V100R003C00SPC515, RH5885 V3 servers with software before V100R003C10SPC102, and XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610 might allow remote attackers to decrypt encrypted data and consequently obtain sensitive information by leveraging selection of an insecure SSL encryption algorithm. Intelligent Baseboard Management Controller (iBMC) en servidores Huawei RH1288 V3 con software anterior a V100R003C00SPC613, servidores RH2288 V3 con software anterior a V100R003C00SPC617, servidores RH2288H V3 con software anterior a V100R003C00SPC515, servidores RH5885 V3 con software anterior a V100R003C10SPC102 y XH620 V3, XH622 V3 y servidores XH628 V3 con software anterior a V100R003C00SPC610 podría permitir a atacantes remotos descepcriptar datos encriptados y consecuentemente obtener información sensible, mediante el aprovechamiento de la selección de un cifrado de algoritmo inseguro SSL. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-02-server-en http://www.securityfocus.com/bid/92623 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-310: Cryptographic Issues •