SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5293

Some Huawei products have a memory leak vulnerability when handling some messages.

MEDIUM 6.5EPSS 0.87%

Does this matter?

Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.

Description

Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.87% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-401
Affected
huawei/ar120-s firmware · huawei/ar1200 firmware · huawei/ar1200-s firmware · huawei/ar150 firmware · huawei/ar150-s firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar200-s firmware · huawei/ar2200 firmware · huawei/ar2200-s firmware · huawei/ar3200 firmware · huawei/ar3600 firmware · huawei/netengine16ex firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.