ZeroHour

CVE-2019-5291

CVSS 3.1
5.9 medium
EPSS
<1%p29
Published
()
Modified
Description

Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

Vendors
huawei
Products
ar120-s firmware, ar1200 firmware, ar1200-s firmware, ar150 firmware, ar150-s firmware, ar160 firmware, ar200 firmware, ar200-s firmware, ar2200 firmware, ar2200-s firmware, ar3200 firmware, ar3600 firmware
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.