6.5
CVE-2019-5293
- EPSS 0.39%
- Veröffentlicht 13.11.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:44:41
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ Ar120-s Firmware Versionv200r005c20
Huawei ≫ Ar120-s Firmware Versionv200r006c10
Huawei ≫ Ar1200 Firmware Versionv200r005c20
Huawei ≫ Ar1200 Firmware Versionv200r006c10
Huawei ≫ Ar1200-s Firmware Versionv200r005c20
Huawei ≫ Ar1200-s Firmware Versionv200r006c10
Huawei ≫ Ar150 Firmware Versionv200r005c20
Huawei ≫ Ar150 Firmware Versionv200r006c10
Huawei ≫ Ar150-s Firmware Versionv200r005c20
Huawei ≫ Ar150-s Firmware Versionv200r006c10
Huawei ≫ Ar160 Firmware Versionv200r005c20
Huawei ≫ Ar160 Firmware Versionv200r006c10
Huawei ≫ Ar200 Firmware Versionv200r005c20
Huawei ≫ Ar200 Firmware Versionv200r006c10
Huawei ≫ Ar200-s Firmware Versionv200r005c20
Huawei ≫ Ar200-s Firmware Versionv200r006c10
Huawei ≫ Ar2200 Firmware Versionv200r005c20
Huawei ≫ Ar2200 Firmware Versionv200r006c10
Huawei ≫ Ar2200-s Firmware Versionv200r005c20
Huawei ≫ Ar2200-s Firmware Versionv200r006c10
Huawei ≫ Ar3200 Firmware Versionv200r005c20
Huawei ≫ Ar3200 Firmware Versionv200r006c10
Huawei ≫ Ar3600 Firmware Versionv200r006c10
Huawei ≫ Netengine16ex Firmware Versionv200r005c20
Huawei ≫ Netengine16ex Firmware Versionv200r006c10
Huawei ≫ Srg1300 Firmware Versionv200r005c20
Huawei ≫ Srg1300 Firmware Versionv200r006c10
Huawei ≫ Srg2300 Firmware Versionv200r005c20
Huawei ≫ Srg2300 Firmware Versionv200r006c10
Huawei ≫ Srg3300 Firmware Versionv200r005c20
Huawei ≫ Srg3300 Firmware Versionv200r006c10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.39% | 0.568 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.