← Voltar para CVEs
CVE-2019-5294
HIGH7.5
Descricao
There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the affected products. Due to a buffer read overflow error when parsing the message, successful exploit may cause some service to be abnormal.
Detalhes CVE
Pontuacao CVSS v3.17.5
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado11/13/2019
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
huawei:ar120-shuawei:ar120-s_firmwarehuawei:ar1200huawei:ar1200-shuawei:ar1200-s_firmwarehuawei:ar1200_firmwarehuawei:ar150huawei:ar150-shuawei:ar150-s_firmwarehuawei:ar150_firmwarehuawei:ar160huawei:ar160_firmwarehuawei:ar200huawei:ar200-shuawei:ar200-s_firmwarehuawei:ar200_firmwarehuawei:ar2200huawei:ar2200-shuawei:ar2200-s_firmwarehuawei:ar2200_firmwarehuawei:ar3200huawei:ar3200_firmwarehuawei:ar3600huawei:ar3600_firmwarehuawei:netengine16exhuawei:netengine16ex_firmwarehuawei:srg1300huawei:srg1300_firmwarehuawei:srg2300huawei:srg2300_firmwarehuawei:srg3300huawei:srg3300_firmware
Fraquezas (CWE)
CWE-125
Referencias
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191023-01-buffer-en(psirt@huawei.com)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191023-01-buffer-en(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.