SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19417

The SIP module of some Huawei products have a denial of service (DoS) vulnerability.

HIGH 7.5EPSS 0.88%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.88% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-119
Affected
huawei/ar120-s firmware · huawei/ar1200 firmware · huawei/ar1200-s firmware · huawei/ar150 firmware · huawei/ar150-s firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar200-s firmware · huawei/ar2200 firmware · huawei/ar2200-s firmware · huawei/ar3200 firmware · huawei/ar3600 firmware · huawei/ar510 firmware · huawei/dp300 firmware · huawei/ips module firmware · huawei/ngfw module firmware · huawei/nip6300 firmware · huawei/nip6600 firmware · huawei/nip6800 firmware · huawei/netengine16ex firmware · +30 more
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.