4 results (0.002 seconds)

CVSS: 5.9EPSS: 0%CPEs: 40EXPL: 0

08 Jan 2018 — Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal. Múltiples switches Huawei Campus permiten que los atacantes remotos enumeren los nombres de usuario mediante vectores que involucren el uso de SSH por el terminal de mantenimiento. • http://www.huawei.com/us/psirt/security-advisories/2014/hw-362701 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 0

22 Nov 2017 — S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping. S3300 V100R006C05 tiene una vulnerabilidad de oscilación de Ethernet in the First Mile (EFM) debido a la falta de comprobación de consistencia de tiempo-longitud-valor (TLV). Un atacante podría manipular paquetes mal formados y enviarlos a un dispositivo para provocar la oscilac... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170118-01-vrp-en • CWE-417: Communication Channel Errors •

CVSS: 7.8EPSS: 0%CPEs: 121EXPL: 0

08 Jun 2017 — The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message. En varios modelos de switch de la serie Huawei Campus, la pila IP permite a atacantes remotos causar una denegación de servicio (reinicio) a través de un mensaje de solicitud ICMP manipulado. • http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-427449.htm • CWE-20: Improper Input Validation •

CVSS: 7.8EPSS: 0%CPEs: 59EXPL: 0

02 Apr 2017 — Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earlier versions; S5300, S5700, S6300, S6700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions; S7700, S9300, S9300E, S9700 with software V100R006, V200R001, V200R002, V200R003, V200R005C00SPC300 and earlier versions could allow remote attackers to send a special SSH packet ... • http://www.huawei.com/en/psirt/security-advisories/hw-373182 • CWE-20: Improper Input Validation •