15 results (0.007 seconds)

CVSS: 6.8EPSS: 0%CPEs: 57EXPL: 0

27 Oct 2021 — There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device. Se presenta una vulnerabilidad de inyección CSV en ManageOne, iManager NetEco e iManager NetEco 6000. Un atacante con altos privilegios puede explotar esta vulner... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20211020-01-csv-en • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 6.7EPSS: 0%CPEs: 1EXPL: 0

02 Aug 2021 — There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of verification when they are be called. Attackers can exploit this vulnerability by performing these files to cause privilege escalation attack. This can compromise normal service. Se presenta una vulnerabilidad de escalada de privilegios en Huawei ManageOne versión 8.0.0. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210714-01-pe-en • CWE-20: Improper Input Validation •

CVSS: 4.7EPSS: 0%CPEs: 19EXPL: 0

29 Jun 2021 — There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O read by multiple threads. An attacker with the root permission can exploit this vulnerability by performing some operations. Successful exploitation of this vulnerability may cause the system to crash. Affected product versions include: ManageOne 6.5.1.SPC200, 8.0.0,8.0.0-LCND81, 8.0.0.SPC100, 8.0.1,8.0.RC2, 8.0.RC3, 8.0.RC3.SPC100;SMC2.0 V600R019C10SPC700,V600R019C10SPC702, V600R019C10SPC7... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-racecondition-en • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 6.5EPSS: 0%CPEs: 38EXPL: 0

20 May 2021 — There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal. Se presenta una vulnerabilidad de denegación de servicio en algunas versiones de ManageOne. En escenarios específicos, debido a la verificación insuficiente del parámetro, un atacante puede diseñar algún parámetro específico. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-dos-en • CWE-345: Insufficient Verification of Data Authenticity •

CVSS: 5.3EPSS: 0%CPEs: 33EXPL: 0

20 May 2021 — There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful exploit may cause some services abnormal. Se presenta una vulnerabilidad de denegación de servicio en algunas versiones de ManageOne. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-02-dos-en •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

22 Mar 2021 — There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service. Se presenta una vulnerabilidad de escalamiento de privilegios local en algunas versiones de ManageOne. Un atacante local autenticado podría llevar a cabo operaciones específicas para explotar esta vulnerabilidad. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210218-01-privilege-en •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 0

22 Mar 2021 — There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected product versions include: ManageOne versions 8.0.0, 8.0.1. Se presenta una vulnerabilidad de asignación inapropiada de permisos en el producto Huawei ManageOne. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210203-01-manageone-en • CWE-276: Incorrect Default Permissions •

CVSS: 7.5EPSS: 0%CPEs: 9EXPL: 0

06 Feb 2021 — Some Huawei products have an inconsistent interpretation of HTTP requests vulnerability. Attackers can exploit this vulnerability to cause information leak. Affected product versions include: CampusInsight versions V100R019C10; ManageOne versions 6.5.1.1, 6.5.1.SPC100, 6.5.1.SPC200, 6.5.1RC1, 6.5.1RC2, 8.0.RC2. Affected product versions include: Taurus-AL00A versions 10.0.0.1(C00E1R1P1). Algunos productos de Huawei presentan una vulnerabilidad de interpretación inconsistente de peticiones HTTP. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210120-01-http-en • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') •

CVSS: 7.8EPSS: 0%CPEs: 41EXPL: 0

06 Feb 2021 — There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions 6.5.0,6.5.0.SPC100.B210,6.5.1.1.B010,6.5.1.1.B020,6.5.1.1.B030,6.5.1.1.B040,6.5.1.SPC100.B050,6.5.1.SPC101.B010,6.5.1.SPC101.B040,6.5.1.SPC200,6.5.1.SPC200.B010,6.5.1.SPC200.B030,6.5.1.SPC200.B040,6.5.1.SPC200.B... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210120-02-privilege-en •

CVSS: 4.9EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2021 — There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject CSV files to the target device. Se presenta una vulnerabilidad de inyección de CSV en ManageOne versión 8.0.1. Un atacante con privilegio común puede explotar esta vulnerabilidad por medio de algunas operaciones para inyectar l... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-01-csvinjection-en • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •