5.9
CVE-2019-5291
- EPSS 0.22%
- Veröffentlicht 13.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:41
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Ar120-s Firmware Versionv200r005c20
Huawei ≫ Ar120-s Firmware Versionv200r006c10
Huawei ≫ Ar120-s Firmware Versionv200r007c00
Huawei ≫ Ar120-s Firmware Versionv200r008c50
Huawei ≫ Ar1200 Firmware Versionv200r005c00
Huawei ≫ Ar1200 Firmware Versionv200r006c10
Huawei ≫ Ar1200 Firmware Versionv200r007c00
Huawei ≫ Ar1200 Firmware Versionv200r008c50
Huawei ≫ Ar1200-s Firmware Versionv200r005c20
Huawei ≫ Ar1200-s Firmware Versionv200r006c10
Huawei ≫ Ar1200-s Firmware Versionv200r007c00
Huawei ≫ Ar1200-s Firmware Versionv200r008c50
Huawei ≫ Ar150 Firmware Versionv200r005c20
Huawei ≫ Ar150 Firmware Versionv200r006c10
Huawei ≫ Ar150 Firmware Versionv200r007c00
Huawei ≫ Ar150 Firmware Versionv200r008c50
Huawei ≫ Ar150-s Firmware Versionv200r005c20
Huawei ≫ Ar150-s Firmware Versionv200r006c10
Huawei ≫ Ar150-s Firmware Versionv200r007c00
Huawei ≫ Ar150-s Firmware Versionv200r008c50
Huawei ≫ Ar160 Firmware Versionv200r005c20
Huawei ≫ Ar160 Firmware Versionv200r006c10
Huawei ≫ Ar160 Firmware Versionv200r007c00
Huawei ≫ Ar160 Firmware Versionv200r008c50
Huawei ≫ Ar200 Firmware Versionv200r005c20
Huawei ≫ Ar200 Firmware Versionv200r006c10
Huawei ≫ Ar200 Firmware Versionv200r007c00
Huawei ≫ Ar200 Firmware Versionv200r008c50
Huawei ≫ Ar200-s Firmware Versionv200r005c20
Huawei ≫ Ar200-s Firmware Versionv200r006c10
Huawei ≫ Ar200-s Firmware Versionv200r007c00
Huawei ≫ Ar200-s Firmware Versionv200r008c50
Huawei ≫ Ar2200 Firmware Versionv200r005c20
Huawei ≫ Ar2200 Firmware Versionv200r006c10
Huawei ≫ Ar2200 Firmware Versionv200r007c00
Huawei ≫ Ar2200 Firmware Versionv200r008c50
Huawei ≫ Ar2200-s Firmware Versionv200r005c20
Huawei ≫ Ar2200-s Firmware Versionv200r006c10
Huawei ≫ Ar2200-s Firmware Versionv200r007c00
Huawei ≫ Ar2200-s Firmware Versionv200r008c50
Huawei ≫ Ar3200 Firmware Versionv200r005c20
Huawei ≫ Ar3200 Firmware Versionv200r006c10
Huawei ≫ Ar3200 Firmware Versionv200r007c00
Huawei ≫ Ar3200 Firmware Versionv200r008c50
Huawei ≫ Ar3600 Firmware Versionv200r006c10
Huawei ≫ Ar3600 Firmware Versionv200r007c00
Huawei ≫ Ar3600 Firmware Versionv200r008c50
Huawei ≫ Cloudengine 12800 Firmware Versionv200r002c10
Huawei ≫ Cloudengine 12800 Firmware Versionv200r002c20
Huawei ≫ Netengine16ex Firmware Versionv200r005c20
Huawei ≫ Netengine16ex Firmware Versionv200r006c10
Huawei ≫ Netengine16ex Firmware Versionv200r007c00
Huawei ≫ Netengine16ex Firmware Versionv200r008c50
Huawei ≫ S6700 Firmware Versionv200r008c00
Huawei ≫ S6700 Firmware Versionv200r010c00spc300
Huawei ≫ S6700 Firmware Versionv200r010c00spc600
Huawei ≫ S6700 Firmware Versionv200r011c00spc200
Huawei ≫ Srg1300 Firmware Versionv200r005c20
Huawei ≫ Srg1300 Firmware Versionv200r006c10
Huawei ≫ Srg1300 Firmware Versionv200r007c00
Huawei ≫ Srg1300 Firmware Versionv200r008c50
Huawei ≫ Srg2300 Firmware Versionv200r005c20
Huawei ≫ Srg2300 Firmware Versionv200r006c10
Huawei ≫ Srg2300 Firmware Versionv200r007c00
Huawei ≫ Srg2300 Firmware Versionv200r008c50
Huawei ≫ Srg3300 Firmware Versionv200r005c20
Huawei ≫ Srg3300 Firmware Versionv200r006c10
Huawei ≫ Srg3300 Firmware Versionv200r007c00
Huawei ≫ Srg3300 Firmware Versionv200r008c50
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.449 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.