This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Vulnerability Handling
Huawei PSIRT handles reported potential vulnerabilities in accordance with the vulnerability handling process.
Huawei Vulnerability Management Principles
One of our key development strategies is to uphold the continuous construction and full implementation of the end-to-end global cyber security assurance system. As such, we have established a sustainable and reliable vulnerability management system, which covers policies, organizations, processes, management, technologies, and specifications. Furthermore, we continue to address challenges together with external stakeholders in an open manner.
To clarify our position and stance on vulnerabilities and to standardize end-to-end vulnerability management operations, we have proposed five basic principles for vulnerability management:
1. Harm and risk reduction
Reducing or eliminating the harm and security risks caused by vulnerabilities in Huawei products, solutions, and services to customers/users is not only our vision for vulnerability management, but also our guidelines for vulnerability handling and disclosure.
2. Vulnerability reduction and mitigation
Despite the industry consensus that vulnerabilities are inevitable, we still strive to: (1) Take actions to reduce vulnerabilities in our products and services. (2) Promptly provide risk mitigations to customers/users after vulnerabilities are found in our products and services.
3. Proactive management
Vulnerability issues need to be resolved jointly with upstream and downstream partners throughout the supply chain. We actively identify our vulnerability management responsibilities, help the upstream and downstream understand the management boundaries and requirements (including applicable laws/regulations on business operation, contract requirements, and applicable public standards), and build a system to proactively manage vulnerabilities.
4. Continuous optimization
Cyber security is evolving. As threats evolve, defenders need to maintain continuous innovation. We will continue to optimize our vulnerability management processes and standards, learn from industry standards and best practices, and improve the maturity of our vulnerability management.
5. Openness and collaboration
We maintain an open and collaborative approach to strengthen our connections with the supply chain and the external security ecosystem, including our upstream and downstream partners, security researchers, security companies, and security regulators. We will enhance collaboration with stakeholders during vulnerability management to build reliable partnerships.
In compliance with these principles and with industry standards including ISO/IEC 30111, ISO/IEC 29147, and ISO/SAE 21434, we have established a robust vulnerability management process. We always uphold our responsibilities and strive to make every effort possible to protect customers and reduce risks caused by vulnerability exploitation
Huawei's Commitment to Product Security
Throughout the product development lifecycle, Huawei explicitly prohibits any product behavior or function that intentionally leads to issues such as unauthorized access, sensitive information leakage, or security function bypassing. This includes but is not limited to:
- Unpublished interfaces and credentials (including accounts, passwords, ports, command lines, and parameters)
- Malicious software, including viruses and Trojan horses
- Hard-coded authentication credentials or encryption/decryption keys
Huawei encourages all parties to report this relevant information to Huawei PSIRT. Huawei will prioritize handling these behaviors with the highest priority.
Vulnerability Handling Process
We are committed to improving the security of our products to fully support the secure operations of customers' networks and services. We have always attached great importance to vulnerability management in product development and maintenance, and have established a robust vulnerability handling process based on ISO/IEC 30111, ISO/IEC 29147, and other standards to improve product security and ensure timely response to vulnerabilities.

- Vulnerability awareness: Receive and collect suspected vulnerabilities in products.
- Validation & assessment: Confirm the validity and impact scope of suspected vulnerabilities.
- Vulnerability remediation: Develop and implement vulnerability risk mitigation solutions
- Vulnerability disclosure: Release vulnerability remediation information to customers.
- Continuous improvement: Make continuous improvement based on customers' comments and practices.
Prompt vulnerability awareness is a critical prerequisite for timely response. We encourage security researchers, industry organizations, customers, and suppliers to proactively report suspected vulnerabilities to our PSIRT, and require upstream suppliers to promptly report vulnerabilities in deliverables to us. Meanwhile, we proactively monitor well-known public vulnerability databases, open source communities, security websites, and other sources to swiftly detect vulnerabilities related to Huawei products. We manage all suspected vulnerabilities that are known to us and investigate the impact on all product versions that have not reached the end of service & support (EOS). Based on industry best practices, we strongly recommend that customers regularly review the availability of product support to ensure that they are entitled to software updates.
After receiving any suspected vulnerability, our PSIRT will work with the relevant product team to analyze/validate the vulnerability, assess its severity based on its actual impact on products, determine its remediation priority, and develop remediations (including workarounds, patches/versions, and other risk mitigations that can be implemented by customers). Sticking to the principles of harm and risk reduction, we release vulnerability information to stakeholders and help customers assess the actual risks of vulnerabilities to their networks.
If Huawei discovers vulnerabilities in a supplier's products or services during the product development, delivery, or deployment process, it will request remediation from the supplier. For open-source software vulnerabilities, Huawei adheres to the vulnerability management policies of the open-source community and reports suspected vulnerabilities to the open-source community in a responsible and risk-mitigating manner to drive the timely release of patches. Furthermore, Huawei contributes vulnerability remediations to the open-source communities. To facilitate coordinated vulnerability disclosure, if the upstream open-source community responds within 90 days, Huawei will adhere to the negotiated embargo period policy. If progress has been made but the default 90-day period is insufficient to provide a patch or other mitigations, Huawei will work with the open-source community to adjust the timeframe. If no response is received within the specified period, Huawei will attempt to remediate the vulnerability and disclose it to customers in a responsible manner to help customers mitigate the risk. For vulnerabilities discovered in products or services of suppliers or open source software, Huawei will preferentially notify relevant parties through PGP-encrypted email.
Huawei PSIRT will coordinate with the reporters to handle the vulnerabilities. Huawei may either function as a coordinator or engage an industry-recognized third-party coordination center to transfer vulnerability information to other vendors and standards organizations to promote vulnerability resolution. If the vulnerability involves standards or protocols, it is recommended that the reporter notify industry organizations when reporting the vulnerability to Huawei PSIRT. For example, vulnerabilities related to 3GPP protocols can be reported to the GSMA Coordinated Vulnerability Disclosure (CVD) program.
Adhering to the principle of continuous optimization, Huawei continuously improves its product security and vulnerability handling process.
Throughout the vulnerability handling process, Huawei PSIRT strictly ensures that vulnerability information is transferred only among personnel directly involved in addressing the vulnerability. Additionally, Huawei requests that reporters maintain confidentiality of the vulnerability information until a complete solution is available to customers.
Huawei will take necessary and reasonable measures to protect the obtained data in compliance with applicable legal and regulatory requirements. Huawei will not proactively share or disclose the aforementioned data to other parties unless required by applicable laws, or explicitly requested by an affected customer—provided that such a request does not compromise the legitimate rights and interests of other customers.
Vulnerability Risk Assessment
Vulnerability Severity Rating
Huawei assesses the severity of suspected vulnerabilities in its products based on industry standards. Taking the Common Vulnerability Scoring System (CVSS) as an example, the model comprises three metric groups: Base, Temporal, and Environmental. Generally, Huawei provides the Base score, and in certain cases, provides the Temporal score, and Environmental score for typical scenarios. Huawei encourages end users to calculate an Environmental score based on their network conditions. This score is used as the final vulnerability score in the specific environment, thereby supporting their vulnerability mitigation and deployment decisions.
Huawei uses the Security Severity Rating (SSR) as a straightforward classification method, categorizing vulnerabilities into five levels: Critical, High, Medium, Low, and Informational.
It is important to note that the security severity does not represent the actual risk posed by a vulnerability. To enable more precise security protection and risk response, Huawei uses a risk assessment model (Risk = Likelihood × Impact) to identify High-Risk vulnerabilities and prioritize their remediation.
High-Risk Vulnerability Assessment
Huawei will classify a vulnerability as High Risk if it meets all of the following criteria:
- The CVSS Base score is 7.0 or higher.
- An exploit for the vulnerability is available or likely to become available for Huawei products, and the vulnerability is being or is likely to be actively exploited.
- In typical deployment scenarios, the product is exposed to an untrusted environment.
- The vulnerability has a significant impact on business operations.
Third-Party Software Vulnerability
Due to the diversity of ways and scenarios in which third-party software/components are integrated into Huawei products, Huawei will adjust the vulnerability scores of third-party software or components based on specific scenarios to reflect the actual impact of vulnerabilities. For example, if the affected module of the third-party software/components is not called, the vulnerability is considered "not exploitable and has no impact." If the existing assessment framework cannot cover all dimensions, Huawei is responsible for interpreting the assessment result.
For a high-risk third-party vulnerability, Huawei will review all product versions that have not reached the EOS. Upon confirming a vulnerability as High Risk, Huawei will release a Security Notice (SN) within 24 hours to inform relevant customers of the handling progress. When a vulnerability remediation becomes available, Huawei will release a Security Advisory (SA) to support customers in risk decision-making and mitigation. For third-party vulnerabilities that are not classified as High Risk, Huawei will document them in Release Notes (RNs).
Vulnerability Disclosure
Disclosure Strategy
Huawei adopts a responsible disclosure strategy and adheres to the principle of notifying affected parties. Specifically, Huawei has established a vulnerability disclosure mechanism for customers who purchase Huawei products and solutions, enabling them to make informed decisions regarding vulnerability risks.
Disclosure Types
Huawei discloses vulnerability information externally using the following types:
- Security Advisory (SA): An SA contains information such as the vulnerability severity rating, impacts on services, and remediation. SAs are used to release information and remediations for critical and high-risk vulnerabilities directly related to Huawei products. In addition to providing downloadable content in the Common Vulnerability Reporting Framework (CVRF) format, Huawei also offers the option of the Common Security Advisory Framework (CSAF) format, which is designed to describe vulnerability information in machine-readable format (JSON/XML) to facilitate the use of automated tools for affected customers.
- Security Notice (SN): An SN contains responses to publicly discussed security topics related to Huawei products, including both vulnerability-related and non-vulnerability-related topics. SNs are used to publish information on issues assessed as Informational under the SSR, such as topics discussed in public forums (e.g., blogs or discussion lists). Additionally, in special scenarios where a vulnerability in a Huawei product version may attract widespread public attention or where Huawei has observed active exploitation of a vulnerability, an SN is also issued as a response to inform relevant customers of Huawei's progress in addressing the vulnerability.
- Release Notes (RN): An RN contains a full list of vulnerabilities that have been remediated in a given product version or patch. As part of the deliverables released with a product version or patch, the RN describes all remediated vulnerabilities. To facilitate customers in comprehensively assessing the vulnerability risks in a version or patch, the RN also includes vulnerability information and remediations published in SAs.
Disclosure Channels
Huawei has established a multi-channel vulnerability disclosure mechanism to help customers promptly obtain vulnerability remediation information and reduce risks:
- Delivery of RNs: A comprehensive list of all vulnerabilities remediated in each product release is provided alongside product version releases.
- Vulnerability disclosure portal: A self-service subscription service is available for customers to promptly receive SAs for critical and high-risk vulnerabilities and SNs.
- Automation service: A machine-to-machine interface based on CSAF is provided to enable automated sharing of vulnerability information.
Huawei publishes SAs and SNs to help affected customers access vulnerability remediation information. RNs are part of the deliverables for product version or patch releases, and customers can obtain them together with the product version or patch releases.
| Type of Vulnerability Disclosure |
Vulnerability Disclosure Website | Email Notification | Machine-Readable Interface1 | Support Website |
| SA | Yes | Yes | Yes | No |
| SN | Yes | Yes | Yes | — |
| RN | — | — | — | Yes |
Huawei provides different channels of obtaining vulnerability information for different business domains:
- Carrier business: Disclosure Website
- Enterprise business: Disclosure Website
- Digital Power: Disclosure Website
- Cloud: Disclosure Website
- Consumer business: Disclosure Website
- HiSilicon: Disclosure Website
Remarks:
1. Since June 2024, SAs have been released based on the CSAF V2.0 standard, and Huawei has been qualified as a CSAF Trusted Provider.
Disclosure Plan
Huawei will issue an SN or SA to support customers in making live-network risk decisions when one or more of the following conditions are met:
- For vulnerabilities rated as Critical under the SSR, once Huawei completes the vulnerability response process, it will provide remediations to help customers mitigate live-network risks.
- For vulnerabilities identified as High-Risk that could increase the risk exposure for Huawei customers, Huawei will accelerate the response process. Huawei will notify customers within 24 hours of confirming that the above conditions are met and will continuously provide updates on the vulnerability response progress.
- To minimize global cyber risks, when coordinating disclosure with third parties, Huawei adheres to the CVD strategy to determine the announcement schedule.
Disclosure Schedule
To better help customers develop their patch deployment plans and assess risks, Huawei routinely releases SAs on Wednesdays. Additionally, Huawei may publish SAs outside of the regular schedule under the following circumstances (non-exhaustive list):
- High-Risk vulnerabilities.
- Vulnerabilities disclosed in coordination with third parties.
Note: For Huawei Cloud, Huawei discloses vulnerability information and remediations with reference to Huawei Cloud Security White Paper. For consumer business, Huawei typically discloses vulnerability information and remediations in routine announcements.
How to Obtain Software Updates
Vulnerability management is based on lifecycle milestones of products/software versions. Huawei PSIRT manages the vulnerabilities of all products/versions before they reach the EOS. Vulnerability remediation is provided before the End of Full Support (EOFS). After EOFS, remediations for vulnerabilities rated as Critical or High under the SSR will be provided at Huawei's discretion. A product team may define additional milestones beyond those specified in this policy. For details about vulnerability remediation support for these milestones, refer to the specific product documentation.
You can mitigate vulnerability risks by patching or upgrading to a new product/software version according to the contract. You can only obtain and use software versions that have valid (currently activated) licenses. Remediating a vulnerability in a product/version does not entitle you to obtain a new software license, additional software functions/features, or a major version upgrade. You can contact Huawei support engineers or TAC to obtain versions or patches:
If you are our Carrier Business customer, click here.
If you are our Enterprise Business customer, click here.
If you are our Consumer Business customer, you can perform an online update or click here.
If you are our Digital Power customer, click here.
If you are our Huawei Cloud customer, click here.
If you are our HiSilicon customer, click here.
Disclaimer & Rights Reserved
If this document is available in multiple languages, the Chinese version shall prevail. The policy described in this document does not constitute warranties or commitments, nor does it form part of any contract. Huawei may adjust it as appropriate
We reserve the right to change or update this document at any time as necessary to increase transparency or respond more actively. Example updates include:
- Feedback from customers, regulators, the industry, or other stakeholders
- Changes to the overall policy
- Introduction of best practices
As changes to this policy are posted, we will revise the "Update Date" at the bottom of this policy.
Definition
The following table lists the definitions used in this policy.
Updated 2026.9.15