6.5

CVE-2019-5293

Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HuaweiAr120-s Firmware Versionv200r005c20
   HuaweiAr120-s Version-
HuaweiAr120-s Firmware Versionv200r006c10
   HuaweiAr120-s Version-
HuaweiAr1200 Firmware Versionv200r005c20
   HuaweiAr1200 Version-
HuaweiAr1200 Firmware Versionv200r006c10
   HuaweiAr1200 Version-
HuaweiAr1200-s Firmware Versionv200r005c20
   HuaweiAr1200-s Version-
HuaweiAr1200-s Firmware Versionv200r006c10
   HuaweiAr1200-s Version-
HuaweiAr150 Firmware Versionv200r005c20
   HuaweiAr150 Version-
HuaweiAr150 Firmware Versionv200r006c10
   HuaweiAr150 Version-
HuaweiAr150-s Firmware Versionv200r005c20
   HuaweiAr150-s Version-
HuaweiAr150-s Firmware Versionv200r006c10
   HuaweiAr150-s Version-
HuaweiAr160 Firmware Versionv200r005c20
   HuaweiAr160 Version-
HuaweiAr160 Firmware Versionv200r006c10
   HuaweiAr160 Version-
HuaweiAr200 Firmware Versionv200r005c20
   HuaweiAr200 Version-
HuaweiAr200 Firmware Versionv200r006c10
   HuaweiAr200 Version-
HuaweiAr200-s Firmware Versionv200r005c20
   HuaweiAr200-s Version-
HuaweiAr200-s Firmware Versionv200r006c10
   HuaweiAr200-s Version-
HuaweiAr2200 Firmware Versionv200r005c20
   HuaweiAr2200 Version-
HuaweiAr2200 Firmware Versionv200r006c10
   HuaweiAr2200 Version-
HuaweiAr2200-s Firmware Versionv200r005c20
   HuaweiAr2200-s Version-
HuaweiAr2200-s Firmware Versionv200r006c10
   HuaweiAr2200-s Version-
HuaweiAr3200 Firmware Versionv200r005c20
   HuaweiAr3200 Version-
HuaweiAr3200 Firmware Versionv200r006c10
   HuaweiAr3200 Version-
HuaweiAr3600 Firmware Versionv200r006c10
   HuaweiAr3600 Version-
HuaweiNetengine16ex Firmware Versionv200r005c20
   HuaweiNetengine16ex Version-
HuaweiNetengine16ex Firmware Versionv200r006c10
   HuaweiNetengine16ex Version-
HuaweiSrg1300 Firmware Versionv200r005c20
   HuaweiSrg1300 Version-
HuaweiSrg1300 Firmware Versionv200r006c10
   HuaweiSrg1300 Version-
HuaweiSrg2300 Firmware Versionv200r005c20
   HuaweiSrg2300 Version-
HuaweiSrg2300 Firmware Versionv200r006c10
   HuaweiSrg2300 Version-
HuaweiSrg3300 Firmware Versionv200r005c20
   HuaweiSrg3300 Version-
HuaweiSrg3300 Firmware Versionv200r006c10
   HuaweiSrg3300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.568
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.