
CVE-2021-22339
https://notcve.org/view.php?id=CVE-2021-22339
20 May 2021 — There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient verification of the parameter, an attacker may craft some specific parameter. Successful exploit may cause some services abnormal. Se presenta una vulnerabilidad de denegación de servicio en algunas versiones de ManageOne. En escenarios específicos, debido a la verificación insuficiente del parámetro, un atacante puede diseñar algún parámetro específico. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-01-dos-en • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2021-22409
https://notcve.org/view.php?id=CVE-2021-22409
20 May 2021 — There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation of a function of a module. When the service pressure is heavy, there is a low probability that an exception may occur. Successful exploit may cause some services abnormal. Se presenta una vulnerabilidad de denegación de servicio en algunas versiones de ManageOne. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210428-02-dos-en •

CVE-2021-22299
https://notcve.org/view.php?id=CVE-2021-22299
06 Feb 2021 — There is a local privilege escalation vulnerability in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. Affected product versions include: ManageOne versions 6.5.0,6.5.0.SPC100.B210,6.5.1.1.B010,6.5.1.1.B020,6.5.1.1.B030,6.5.1.1.B040,6.5.1.SPC100.B050,6.5.1.SPC101.B010,6.5.1.SPC101.B040,6.5.1.SPC200,6.5.1.SPC200.B010,6.5.1.SPC200.B030,6.5.1.SPC200.B040,6.5.1.SPC200.B... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210120-02-privilege-en •

CVE-2020-9115
https://notcve.org/view.php?id=CVE-2020-9115
30 Nov 2020 — ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device. Las versiones 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, 6.5.1.1.B050, 8.0.0 y 8.0.1 de ManageOne... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201125-01-commandinjection-en • CWE-20: Improper Input Validation CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2020-1862
https://notcve.org/view.php?id=CVE-2020-1862
20 Mar 2020 — There is a double free vulnerability in some Huawei products. A local attacker with low privilege may perform some operations to exploit the vulnerability. Due to doubly freeing memory, successful exploit may cause some service abnormal. Affected product versions include:CampusInsight versions V100R019C00;ManageOne versions 6.5.RC2.B050. Se presenta una vulnerabilidad de doble liberación en algunos productos Huawei. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200318-01-free-en • CWE-415: Double Free •

CVE-2019-5289
https://notcve.org/view.php?id=CVE-2019-5289
13 Nov 2019 — Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. Successful exploit of this vulnerability could allow the attacker to crash the database on the standby node. La base de datos OLTP de Gauss100 en ManageOne con versiones de 6.5.0, hay una vulnerabilidad de lectura fuera de límites debido a las insuficie... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190925-01-database-en • CWE-125: Out-of-bounds Read •

CVE-2019-14835 – kernel: vhost-net: guest to host kernel escape during migration
https://notcve.org/view.php?id=CVE-2019-14835
17 Sep 2019 — A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. Se encontró un fallo de desbordamiento de búfer, en las versiones desde 2.6.34 hasta 5.2.x, en la manera en que la funcionalidad vhost d... • http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00064.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •