SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5291

Some Huawei products have an insufficient verification of data authenticity vulnerability.

MEDIUM 5.9EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.36% probability · 29th percentile
CISA KEV
Not listed
Weakness
CWE-345
Affected
huawei/ar120-s firmware · huawei/ar1200 firmware · huawei/ar1200-s firmware · huawei/ar150 firmware · huawei/ar150-s firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar200-s firmware · huawei/ar2200 firmware · huawei/ar2200-s firmware · huawei/ar3200 firmware · huawei/ar3600 firmware · huawei/cloudengine 12800 firmware · huawei/netengine16ex firmware · huawei/s6700 firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.