Huawei Vulnerabilities and Affected Products
Vulnerabilities associated with Magic UI.
Products
Clear product- HarmonyOS1,089 vulnerabilities
- EMUI756 vulnerabilities
- Magic UI200 vulnerabilities
- NIP680019 vulnerabilities
- Secospace USG660015 vulnerabilities
- USG950012 vulnerabilities
- IPS Module11 vulnerabilities
- NGFW Module11 vulnerabilities
- Secospace USG630011 vulnerabilities
- Secospace USG650011 vulnerabilities
- HUAWEI Mate 2010 vulnerabilities
- NIP630010 vulnerabilities
- NIP660010 vulnerabilities
- Harmony OS8 vulnerabilities
- HUAWEI P30 Pro7 vulnerabilities
- USG6000V7 vulnerabilities
- HUAWEI Mate 20 Pro6 vulnerabilities
- HUAWEI P306 vulnerabilities
- PCManager6 vulnerabilities
- CloudEngine 128005 vulnerabilities
- CloudEngine 58005 vulnerabilities
- CloudEngine 68005 vulnerabilities
- CloudEngine 78005 vulnerabilities
- CurieM-WFG9B5 vulnerabilities
- Emily-L29C5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36601HIGH | Out-of-bounds write vulnerability in the kernel modules. Successful exploitation of this vulnerability may cause a panic reboot. CWE-787Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36600HIGH | Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart. CWE-787Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.559% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39003CRITICAL | Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components. CWE-120Sep 16, 2022 | CVSS9.1v3.1 | EPSS0.453% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39001HIGH | The number identification module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause data disclosure. CWE-22Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.748% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38997HIGH | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38979HIGH | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-38978HIGH | The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39005HIGH | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. CWE-401Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.564% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39004HIGH | The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. CWE-401Sep 16, 2022 | CVSS7.5v3.1 | EPSS0.506% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39006MEDIUM | The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. CWE-362Sep 16, 2022 | CVSS5.9v3.1 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-39000CRITICAL | The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. Sep 16, 2022 | CVSS9.8v3.1 | EPSS0.551% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40030HIGH | The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidentiality. Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.518% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37005HIGH | The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. CWE-88Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.518% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37003CRITICAL | The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files. CWE-276Aug 9, 2022 | CVSS9.8v3.1 | EPSS0.478% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37004HIGH | The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of this vulnerability may affect the availability. Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.574% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37002CRITICAL | The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background. | CVSS9.8v3.1 | EPSS0.492% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37008HIGH | The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability. CWE-345Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.293% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-37007HIGH | The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect the availability. CWE-125Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.561% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40034HIGH | The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of this vulnerability may affect the availability. Aug 9, 2022 | CVSS7.5v3.1 | EPSS0.561% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40016MEDIUM | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect confidentiality. CWE-863Jul 11, 2022 | CVSS6.5v3.1 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40013MEDIUM | Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will affect integrity. CWE-287Jul 11, 2022 | CVSS6.5v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-40012HIGH | Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality. CWE-668Jul 11, 2022 | CVSS7.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34738HIGH | The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background. Jul 11, 2022 | CVSS7.5v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34737CRITICAL | The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality. CWE-276Jul 11, 2022 | CVSS9.1v3.1 | EPSS0.624% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34742HIGH | The system module has a read/write vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | CVSS7.5v3.1 | EPSS0.818% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |