5.9
CVSSv3

CVE-2019-5291

Published: 13/12/2019 Updated: 19/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei ar120-s_firmware v200r005c20

huawei ar120-s_firmware v200r006c10

huawei ar120-s_firmware v200r007c00

huawei ar120-s_firmware v200r008c50

huawei ar1200_firmware v200r005c00

huawei ar1200_firmware v200r006c10

huawei ar1200_firmware v200r007c00

huawei ar1200_firmware v200r008c50

huawei ar1200-s_firmware v200r005c20

huawei ar1200-s_firmware v200r006c10

huawei ar1200-s_firmware v200r007c00

huawei ar1200-s_firmware v200r008c50

huawei ar150_firmware v200r005c20

huawei ar150_firmware v200r006c10

huawei ar150_firmware v200r007c00

huawei ar150_firmware v200r008c50

huawei ar150-s_firmware v200r005c20

huawei ar150-s_firmware v200r006c10

huawei ar150-s_firmware v200r007c00

huawei ar150-s_firmware v200r008c50

huawei ar160_firmware v200r005c20

huawei ar160_firmware v200r006c10

huawei ar160_firmware v200r007c00

huawei ar160_firmware v200r008c50

huawei ar200_firmware v200r005c20

huawei ar200_firmware v200r006c10

huawei ar200_firmware v200r007c00

huawei ar200_firmware v200r008c50

huawei ar200-s_firmware v200r005c20

huawei ar200-s_firmware v200r006c10

huawei ar200-s_firmware v200r007c00

huawei ar200-s_firmware v200r008c50

huawei ar2200_firmware v200r005c20

huawei ar2200_firmware v200r006c10

huawei ar2200_firmware v200r007c00

huawei ar2200_firmware v200r008c50

huawei ar2200-s_firmware v200r005c20

huawei ar2200-s_firmware v200r006c10

huawei ar2200-s_firmware v200r007c00

huawei ar2200-s_firmware v200r008c50

huawei ar3200_firmware v200r005c20

huawei ar3200_firmware v200r006c10

huawei ar3200_firmware v200r007c00

huawei ar3200_firmware v200r008c50

huawei ar3600_firmware v200r006c10

huawei ar3600_firmware v200r007c00

huawei ar3600_firmware v200r008c50

huawei cloudengine_12800_firmware v200r002c10

huawei cloudengine_12800_firmware v200r002c20

huawei netengine16ex_firmware v200r005c20

huawei netengine16ex_firmware v200r006c10

huawei netengine16ex_firmware v200r007c00

huawei netengine16ex_firmware v200r008c50

huawei s6700_firmware v200r008c00

huawei s6700_firmware v200r010c00spc300

huawei s6700_firmware v200r010c00spc600

huawei s6700_firmware v200r011c00spc200

huawei srg1300_firmware v200r005c20

huawei srg1300_firmware v200r006c10

huawei srg1300_firmware v200r007c00

huawei srg1300_firmware v200r008c50

huawei srg2300_firmware v200r005c20

huawei srg2300_firmware v200r006c10

huawei srg2300_firmware v200r007c00

huawei srg2300_firmware v200r008c50

huawei srg3300_firmware v200r005c20

huawei srg3300_firmware v200r006c10

huawei srg3300_firmware v200r007c00

huawei srg3300_firmware v200r008c50

Vendor Advisories

Some Huawei products has an insufficient verification of data authenticity vulnerability A remote, unauthenticated attacker has to intercept specific packets between two devices, modifies the packets, and sends the modified packets to the peer device Due to insufficient verification of some fields in the packets, an attacker may exploit the vulne ...