CVE-2019-5291
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
13/12/2019
Last modified:
19/12/2019
Description
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:ar120-s_firmware:v200r005c20:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar120-s_firmware:v200r008c50:*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:ar120-s:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200_firmware:v200r005c00:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200_firmware:v200r006c10:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200_firmware:v200r007c00:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200_firmware:v200r008c50:*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:ar1200:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200-s_firmware:v200r005c20:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200-s_firmware:v200r006c10:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200-s_firmware:v200r007c00:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:ar1200-s_firmware:v200r008c50:*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:ar1200-s:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page