VendorsHuaweiumav300r001
Vulnerabilities

Huawei UMA v300r001

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2017-8117
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Published 2017-11-22 · Modified
9.8EPSS 0.011
CVE-2017-8119
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Published 2017-11-22 · Modified
9.8EPSS 0.010
CVE-2017-8120
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Published 2017-11-22 · Modified
9.8EPSS 0.010
CVE-2017-8128
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Published 2017-11-22 · Modified
9.8EPSS 0.010
CVE-2017-8129
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
Published 2017-11-22 · Modified
9.8EPSS 0.010
CVE-2017-8130
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
Published 2017-11-22 · Modified
6.5EPSS 0.007
CVE-2017-8125
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
Published 2017-11-22 · Modified
6.1EPSS 0.005
CVE-2017-8121
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
Published 2017-11-22 · Modified
5.3EPSS 0.007
CVE-2017-8118
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
Published 2017-11-22 · Modified
2.3EPSS 0.002