CVE-2019-19416
published 2020-07-08CVE-2019-19416: The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.88%
55.0th percentile
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.
Affected
743 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | ar120-s | — | — |
| huawei | ar120-s | — | — |
| huawei | ar120-s | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar1200 | — | — |
| huawei | ar1200 | — | — |
| huawei | ar1200 | — | — |
| huawei | ar1200-s | — | — |
| huawei | ar1200-s | — | — |
| huawei | ar1200-s | — | — |
| huawei | ar1200-s | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-08
Published