Vulnerabilidades em Huawei

1.367 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2022-38986CRITICALThe HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulneEPSS 0.5%CVE-2023-46773Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.EPSS 0.5%CVE-2022-37004HIGHThe Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability maEPSS 0.5%CVE-2022-41578CRITICALThe MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation EPSS 0.5%CVE-2022-39012HIGHHuawei Aslan Children's Watch has an improper input validation vulnerability. Successful exploitation may cause the watch's application servEPSS 0.5%CVE-2022-41580CRITICALThe HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause maliciousEPSS 0.5%CVE-2021-40019Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds acceEPSS 0.5%CVE-2023-44099Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.EPSS 0.5%CVE-2022-38982CRITICALThe fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.EPSS 0.5%CVE-2023-46774HIGHVulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.EPSS 0.5%CVE-2023-46762HIGHOut-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46768Multi-thread vulnerability in the idmap module. Successful exploitation of this vulnerability may cause features to perform abnormally.EPSS 0.5%CVE-2023-46765HIGHVulnerability of uncaught exceptions in the NFC module. Successful exploitation of this vulnerability can affect NFC availability.EPSS 0.5%CVE-2023-46760HIGHOut-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46772HIGHVulnerability of parameters being out of the value range in the QMI service module. Successful exploitation of this vulnerability may cause EPSS 0.5%CVE-2023-46761Out-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46770HIGHOut-of-bounds vulnerability in the sensor module. Successful exploitation of this vulnerability may cause mistouch prevention errors on userEPSS 0.5%CVE-2023-46766HIGHOut-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46767HIGHOut-of-bounds write vulnerability in the kernel driver module. Successful exploitation of this vulnerability may cause process exceptions.EPSS 0.5%CVE-2023-46769Use-After-Free (UAF) vulnerability in the dubai module. Successful exploitation of this vulnerability will affect availability.EPSS 0.5%