
CVE-2019-19415
https://notcve.org/view.php?id=CVE-2019-19415
08 Jul 2020 — The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en. El módulo SIP de algun... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en • CWE-20: Improper Input Validation CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-19416
https://notcve.org/view.php?id=CVE-2019-19416
08 Jul 2020 — The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en. El módulo SIP de algun... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en • CWE-20: Improper Input Validation CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2019-19417
https://notcve.org/view.php?id=CVE-2019-19417
08 Jul 2020 — The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en. El módulo SIP de algun... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en • CWE-20: Improper Input Validation CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17310
https://notcve.org/view.php?id=CVE-2017-17310
19 Apr 2018 — Electronic Numbers to URI Mapping (ENUM) module in some Huawei products DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a buffer error vulnerability. An unauthenticated, remote attacker has to control the peer device and send specially crafted ENUM packets to the affected products. Due to insufficient verification of some values in the packets, successful exploit ma... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180418-01-enum-en • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17308
https://notcve.org/view.php?id=CVE-2017-17308
11 Apr 2018 — SCCPX module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 has an invalid memory access vulnerability. An unauthenticated, remote attacker may send specially crafted packets to the affected products. Due to insufficient validation of packets, successful exploit may cause some services abnormal. El módulo SCCPX en Huawei DP300 V500R002C00, RP200 V... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180411-01-sccpx-en • CWE-20: Improper Input Validation •

CVE-2017-15314
https://notcve.org/view.php?id=CVE-2017-15314
09 Mar 2018 — Huawei DP300 V500R002C00, RP200 V500R002C00SPC200, V600R006C00, TE30 V100R001C10SPC300, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC700, V500R002C00SPC200, V500R002C00SPC500, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE40 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V600R006C00, TE50 V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPCb00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a memory leak vulnerabi... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-xml-en • CWE-772: Missing Release of Resource after Effective Lifetime •

CVE-2017-17147
https://notcve.org/view.php?id=CVE-2017-17147
09 Mar 2018 — Huawei DP300 V500R002C00 have an integer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks. Huawei DP300 V500R002C00 tiene una vulnerabilidad de desbordamiento de enteros debido a la falta de validación. Un atacante local autenticado puede manipular archivos XML específicos en los productos afectados y analizar este archivo, lo que resulta en ataques de denegación de ser... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171215-01-xml-en • CWE-190: Integer Overflow or Wraparound •

CVE-2017-17146
https://notcve.org/view.php?id=CVE-2017-17146
09 Mar 2018 — Huawei DP300 V500R002C00 have a buffer overflow vulnerability due to the lack of validation. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks or remote code execution on the device. Huawei DP300 V500R002C00 tiene una vulnerabilidad de desbordamiento de búfer debido a la falta de validación. Un atacante local autenticado puede manipular archivos XML específicos en los productos afectados y analizar este archivo, lo que resu... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171215-01-xml-en • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17303
https://notcve.org/view.php?id=CVE-2017-17303
09 Mar 2018 — Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800; V500R002C00SPC900; V500R002C00SPCa00; RP200 V500R002C00SPC200; V600R006C00; V600R006C00SPC200; V600R006C00SPC300; TE30 V100R001C10SPC300; V100R001C10SPC500; V100R001C10SPC600; V100R001C10SPC700B010; V500R002C00SPC200; V500R002C00SPC50... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171220-01-cidam-en • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-17148
https://notcve.org/view.php?id=CVE-2017-17148
09 Mar 2018 — Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is called. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks. Huawei DP300 V500R002C00 tiene una vulnerabilidad de denegación de servicio (DoS) debido a la falta de validación cuando se llama a malloc. Un atacante local autenticado puede manipular archivos XML específicos en los productos afectados y analizar este archivo, lo que... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171215-01-xml-en • CWE-20: Improper Input Validation •