CVE-2019-19414

CWE-190Integer Overflow3 documents3 sources
Severity
7.5HIGH
EPSS
0.3%
top 44.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 24

Description

There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

NVDhuawei/te30_firmwarev100r001c10, v600r006c00+1
NVDhuawei/te40_firmwarev600r006c00
NVDhuawei/te50_firmwarev600r006c00
NVDhuawei/te60_firmwarev100r001c10, v500r002c00, v600r006c00+2
NVDhuawei/dp300_firmwarev500r002c00

🔴Vulnerability Details

2
GHSA
GHSA-6485-232f-h4jw: There is an integer overflow vulnerability in LDAP server of some Huawei products2022-05-24
CVEList
CVE-2019-19414: There is an integer overflow vulnerability in LDAP server of some Huawei products2020-01-21
CVE-2019-19414 (HIGH CVSS 7.5) | There is an integer overflow vulner | cvebase.io