CVE-2021-22356
https://notcve.org/view.php?id=CVE-2021-22356
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected product versions include: IPS Module V500R005C00SPC100, V500R005C00SPC200; NGFW Module V500R005C00SPC100, V500R005C00SPC200; Secospace USG6300 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; Secospace USG6600 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200; USG9500 V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200. Se presenta una vulnerabilidad de algoritmo seguro débil en los productos de Huawei. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210512-01-infomationleak-en • CWE-327: Use of a Broken or Risky Cryptographic Algorithm •
CVE-2021-22411
https://notcve.org/view.php?id=CVE-2021-22411
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers can exploit this vulnerability by performing multiple abnormal activities to trigger the bad logic and cause out-of-bounds write. This may compromise the normal service of the module.Affected product versions include: NGFW Module versions V500R005C00SPC100,V500R005C00SPC200;Secospace USG6300 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;Secospace USG6500 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200;USG9500 versions V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200. Se presenta una vulnerabilidad de escritura fuera de límites en algunos productos de Huawei. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210506-02-outofbounds-en • CWE-787: Out-of-bounds Write •
CVE-2021-22312
https://notcve.org/view.php?id=CVE-2021-22312
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by sending specific message to the affected product. Due to not release the allocated memory properly, successful exploit may cause some service abnormal. Affected product include some versions of IPS Module, NGFW Module, Secospace USG6300, Secospace USG6500, Secospace USG6600 and USG9500. Se presenta una vulnerabilidad filtrado de memoria en algunos productos de Huawei. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210210-01-memoryleak-en • CWE-401: Missing Release of Memory after Effective Lifetime •
CVE-2020-1866
https://notcve.org/view.php?id=CVE-2020-1866
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when parsing certain crafted DHCP messages. Successful exploit could cause certain service abnormal. Affected product versions include:NIP6800 versions V500R001C30,V500R001C60SPC500,V500R005C00;S12700 versions V200R008C00;S2700 versions V200R008C00;S5700 versions V200R008C00;S6700 versions V200R008C00;S7700 versions V200R008C00;S9700 versions V200R008C00;Secospace USG6600 versions V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00;USG9500 versions V500R001C30SPC300,V500R001C30SPC600,V500R001C60SPC500,V500R005C00. Se presenta una vulnerabilidad de lectura fuera de límites en varios productos. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-09-eudemon-en • CWE-125: Out-of-bounds Read •
CVE-2020-9201
https://notcve.org/view.php?id=CVE-2020-9201
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data past the end of the intended buffer when parsing DHCP messages including crafted parameter. Successful exploit could cause certain service abnormal. Se presenta una vulnerabilidad de lectura fuera de límites en algunas versiones de NIP6800, Secospace USG6600 y USG9500. El software lee los datos más allá del final del búfer previsto cuando se analizan los mensajes DHCP, incluyendo el parámetro diseñado. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-04-eudemon-en • CWE-125: Out-of-bounds Read •