CVE Vulnerabilities

CVE-2019-5259

Improper Privilege Management

Published: Dec 16, 2019 | Modified: Aug 24, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful exploit could cause an information disclosure condition.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Ar120-s_firmware Huawei v200r005c32 (including) v200r005c32 (including)
Ar120-s_firmware Huawei v200r006c10 (including) v200r006c10 (including)
Ar120-s_firmware Huawei v200r007c00 (including) v200r007c00 (including)
Ar120-s_firmware Huawei v200r008c50 (including) v200r008c50 (including)
Ar120-s_firmware Huawei v200r009c00 (including) v200r009c00 (including)
Ar120-s_firmware Huawei v200r010c00 (including) v200r010c00 (including)

Potential Mitigations

References