
CVE-2021-22356
https://notcve.org/view.php?id=CVE-2021-22356
23 Nov 2021 — There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; NGFW Module V500R005C00SPC100, V500R005C00SPC200; Secospace USG6300 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200;... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210512-01-infomationleak-en • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2021-22341
https://notcve.org/view.php?id=CVE-2021-22341
29 Jun 2021 — There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module V500R005C00SPC100,V500R005C00SPC200;NGFW Module V500R005C00SPC100,V500R005C00SPC200;NIP6300 V500R005C00SPC100,V500R005C10SPC200;NIP6600 V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 V500R005C00SPC100,V500R005C00SPC200;Secospace U... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210506-01-memleak-en • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2021-22411
https://notcve.org/view.php?id=CVE-2021-22411
27 May 2021 — There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the module.Affected product versions include: NGFW Module versions V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210506-02-outofbounds-en • CWE-787: Out-of-bounds Write •

CVE-2021-22312
https://notcve.org/view.php?id=CVE-2021-22312
08 Apr 2021 — There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500. Se presenta una vulnerabilidad filtrado de memoria en algunos productos de Huawei. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210210-01-memoryleak-en • CWE-401: Missing Release of Memory after Effective Lifetime •

CVE-2021-22320
https://notcve.org/view.php?id=CVE-2021-22320
22 Mar 2021 — There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. Attackers can exploit this vulnerability by sending malicious messages to an affected module. This can lead to denial of service. Affected product include some versions of IPS Module, NGFW Module, NIP6600, NIP6800, Secospace USG6300, Secospace USG6500 and Secospace USG6600. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210210-03-dos-en •

CVE-2020-1874
https://notcve.org/view.php?id=CVE-2020-1874
28 Feb 2020 — NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer access vulnerability. The software system access an invalid pointer when operator logs in to the device and performs some operations. Successful exploit could cause certain process reboot. Los productos NIP6800; Secospace USG6600; USG9500 versiones de V500R001C30; V500R001C60SPC500; V500R005C00SPC100, presentan una vulnerabilidad de acceso de puntero no válido. El sistema del softw... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-02-invalidpointer-en • CWE-824: Access of Uninitialized Pointer •

CVE-2020-1873
https://notcve.org/view.php?id=CVE-2020-1873
28 Feb 2020 — NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the device reboot. Los productos NIP6800; Secospace USG6600; USG9500 con versiones de V500R001C30; V500R001C60SPC500; V500R005C00SPC100, presentan una vulnerabi... • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200219-01-outofboundread-en • CWE-125: Out-of-bounds Read •

CVE-2020-1827
https://notcve.org/view.php?id=CVE-2020-1827
17 Feb 2020 — Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. An attacker can exploit this vulnerability by sending specific request packets to affected devices. Successful exploit may lead to information leakage. Huawei NIP6800 versiones V500R001C30, V500R001C60SPC500 y V500R005C00SPC100; y Secospace USG6600 y USG9500 versiones... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200212-02-ipsec-en • CWE-404: Improper Resource Shutdown or Release •

CVE-2020-1857
https://notcve.org/view.php?id=CVE-2020-1857
17 Feb 2020 — Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have an information leakage vulnerability. Due to improper processing of some data, a local authenticated attacker can exploit this vulnerability through a series of operations. Successful exploitation may cause information leakage. Huawei NIP6800 versiones V500R001C30, V500R001C60SPC500 y V500R005C00SPC100; y... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200205-01-leakage-en •

CVE-2020-1858
https://notcve.org/view.php?id=CVE-2020-1858
17 Feb 2020 — Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100; and USG9500 versions V500R001C30SPC600, V500R001C60SPC500, and V500R005C00SPC100 have a denial of service vulnerability. Attackers need to perform a series of operations in a special scenario to exploit this vulnerability. Successful exploit may cause the new connections can't be established, result in a denial of service. Los Product... • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200205-01-dos-en •