CVE-2019-5291
published 2019-12-13CVE-2019-5291: Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets…
PriorityP430medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.36%
28.0th percentile
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar120-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200-s_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar1200_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150-s_firmware | — | — |
| huawei | ar150_firmware | — | — |
| huawei | ar150_firmware | — | — |
| huawei | ar150_firmware | — | — |
| huawei | ar150_firmware | — | — |
| huawei | ar160_firmware | — | — |
| huawei | ar160_firmware | — | — |
| huawei | ar160_firmware | — | — |
| huawei | ar160_firmware | — | — |
| huawei | ar200-s_firmware | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-12-13
Published