CVE Vulnerabilities

CVE-2019-5291

Insufficient Verification of Data Authenticity

Published: Dec 13, 2019 | Modified: Dec 19, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Ar120-s_firmware Huawei v200r005c20 (including) v200r005c20 (including)
Ar120-s_firmware Huawei v200r006c10 (including) v200r006c10 (including)
Ar120-s_firmware Huawei v200r007c00 (including) v200r007c00 (including)
Ar120-s_firmware Huawei v200r008c50 (including) v200r008c50 (including)

References