Uma

Vendor:

First CVE: Sep 7, 2016 · Active for 9 years

20
Total CVEs
More Total CVEs than 94% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 74% of tracked products
5.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Uma over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2016
9 years ago
Most Recent CVE
May 16, 2019
2,626 days ago

CVE Severity & Scoring

Uma20 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low3 (15.0%)
High1 (5.0%)
None16 (80.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP
May 16, 20199.899YESYES
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2
Sep 7, 20169.832NONO
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific
Nov 22, 20179.831NONO
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could c
Nov 22, 20179.830NONO
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific
Nov 22, 20179.828NONO
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could c
Nov 22, 20179.828NONO
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could c
Nov 22, 20179.827NONO
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could c
Nov 22, 20179.827NONO
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific
Nov 22, 20179.827NONO
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific
Nov 22, 20179.827NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
1 CVE
5.0% of CVEs· 97th percentile
Metasploit
1 CVE
5.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
5.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Uma

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v300r00197.70.8%00
v200r001148.20.9%00