Home/Product/huawei usg9500 firmware
Product

huawei usg9500 firmware

81 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-22356
all versions
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can expl
5.9MEDIUM
CVE-2021-37129
all versions
There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that
7.5HIGH
CVE-2021-22342
all versions
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privi
4.9MEDIUM
CVE-2021-22411
all versions
There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. Attackers c
6.5MEDIUM
CVE-2021-22360
all versions
There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG
4.9MEDIUM
CVE-2021-22312
all versions
There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerability by s
6.5MEDIUM
CVE-2021-22321
all versions
There is a use-after-free vulnerability in a Huawei product. A module cannot deal with specific operations in special scenarios. A
5.3MEDIUM
CVE-2021-22310
all versions
There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the
4.4MEDIUM
CVE-2021-22309
all versions
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can
7.5HIGH
CVE-2020-9213
all versions
There is a denial of service vulnerability in some huawei products. In specific scenarios, due to the improper handling of the pac
7.5HIGH
CVE-2020-9212
all versions
There is a vulnerability in some version of USG9500 that the device improperly handles the information when a user logs in to devi
6.5MEDIUM
CVE-2020-1866
all versions
There is an out-of-bounds read vulnerability in several products. The software reads data past the end of the intended buffer when
6.5MEDIUM
CVE-2020-9201
all versions
There is an out-of-bounds read vulnerability in some versions of NIP6800, Secospace USG6600 and USG9500. The software reads data p
6.5MEDIUM
CVE-2020-9127
all versions
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege
6.7MEDIUM
CVE-2020-1847
all versions
There is a denial of service vulnerability in some Huawei products. There is no protection against the attack scenario of specific
7.5HIGH
CVE-2020-9101
all versions
There is an out-of-bounds write vulnerability in some products. An unauthenticated attacker crafts malformed packets with specific
6.5MEDIUM
CVE-2019-19417
all versions
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three v
7.5HIGH
CVE-2019-19416
all versions
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three v
7.5HIGH
CVE-2019-19415
all versions
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three v
7.5HIGH
CVE-2020-9099
all versions
Huawei products IPS Module; NGFW Module; NIP6300; NIP6600; NIP6800; Secospace USG6300; Secospace USG6500; Secospace USG6600; USG95
9.8CRITICAL
CVE-2020-1883
all versions
Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this
4.9MEDIUM
CVE-2020-1881
all versions
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a resource
7.5HIGH
CVE-2020-1877
all versions
NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer acces
4.4MEDIUM
CVE-2020-1876
all versions
NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds write v
7.5HIGH
CVE-2020-1875
all versions
NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer a
5.5MEDIUM
CVE-2020-1874
all versions
NIP6800;Secospace USG6600;USG9500 products versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have a invalid pointer ac
5.5MEDIUM
CVE-2020-1873
all versions
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bound
7.5HIGH
CVE-2020-1860
all versions
NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access contr
7.5HIGH
CVE-2020-1814
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200,
5.3MEDIUM
CVE-2020-1830
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200,
5.3MEDIUM
CVE-2020-1816
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200,
7.5HIGH
CVE-2020-1815
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200,
7.5HIGH
CVE-2020-1856
all versions
Huawei NGFW Module, NIP6300, NIP6600, Secospace USG6500, Secospace USG6600, and USG9500 versions V500R001C30, V500R001C60, and V50
7.5HIGH
CVE-2020-1829
all versions
Huawei NIP6800 versions V500R001C30 and V500R001C60SPC500; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C
7.5HIGH
CVE-2020-1827
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001
7.5HIGH
CVE-2020-1858
all versions
Huawei products NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; Secospace USG6600 versions V500R001C30SPC6
7.5HIGH
CVE-2020-1857
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00SPC100; and Secospace USG6600 and USG9500 versions V500R001
5.5MEDIUM
CVE-2020-1828
all versions
Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC
7.5HIGH
CVE-2019-19411
all versions
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C0
3.7LOW
CVE-2020-1871
all versions
USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C0
8.2HIGH
CVE-2019-5275
all versions
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation
7.5HIGH
CVE-2019-5274
all versions
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation
7.5HIGH
CVE-2019-5273
all versions
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation
7.5HIGH
CVE-2019-5272
all versions
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected pro
4.9MEDIUM
CVE-2017-17258
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17257
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17256
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17255
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17254
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17253
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
7.5HIGH
CVE-2017-17252
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-17251
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-17138
all versions
PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V
5.5MEDIUM
CVE-2017-17137
all versions
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R00
5.5MEDIUM
CVE-2017-17136
all versions
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R00
5.5MEDIUM
CVE-2017-17135
all versions
PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R00
5.5MEDIUM
CVE-2017-17297
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-17296
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-17295
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-17162
all versions
Huawei Secospace USG6600 V500R001C30SPC100, Secospace USG6600 V500R001C30SPC200, Secospace USG6600 V500R001C30SPC300, USG9500 V500
5.5MEDIUM
CVE-2017-17157
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
7.5HIGH
CVE-2017-17156
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
7.5HIGH
CVE-2017-17155
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
7.5HIGH
CVE-2017-17154
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
7.5HIGH
CVE-2017-17153
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
7.5HIGH
CVE-2017-17152
all versions
IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH
5.9MEDIUM
CVE-2017-15350
all versions
The Common Open Policy Service Protocol (COPS) module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C3
5.3MEDIUM
CVE-2017-15348
all versions
Huawei IPS Module V500R001C00, NGFW Module V500R001C00, NIP6300 V500R001C00, NIP6600 V500R001C00, Secospace USG6300 V500R001C00, S
7.5HIGH
CVE-2017-15339
all versions
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C3
3.7LOW
CVE-2017-15338
all versions
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C3
3.7LOW
CVE-2017-15337
all versions
The SIP module in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C3
3.7LOW
CVE-2017-15336
all versions
The SIP backup feature in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V5
5.3MEDIUM
CVE-2017-15335
all versions
The SIP backup feature in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V5
5.3MEDIUM
CVE-2017-15334
all versions
The SIP backup feature in Huawei DP300 V500R002C00, IPS Module V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V5
5.3MEDIUM
CVE-2017-15332
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-15331
all versions
Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200
5.3MEDIUM
CVE-2017-8167
all versions
Huawei firewall products USG9500 V500R001C50 has a DoS vulnerability.A remote attacker who controls the peer device could exploit
7.5HIGH
CVE-2014-9137
<= v200r001c01spc800
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earl
8.8HIGH
CVE-2014-9136
<= v200r001c01spc800
Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF a
8.8HIGH
CVE-2016-4577
all versions
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 fire
7.5HIGH
CVE-2016-4576
all versions
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300,
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin